7.5
    High

    CVE-2006-5733

    Last Modified: 3 Nov 2017

    Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang (PNSV lang) cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

    Source:Kacper
    Published:6 Nov 2006
    5
    Medium

    CVE-2006-5732

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in logout.php in T.G.S. CMS 0.1.7 and earlier allows remote attackers to execute arbitrary SQL commands via the myauthorid cookie.

    Source:Kacper
    Published:6 Nov 2006
    6.4
    Medium

    CVE-2006-5731

    Last Modified: 14 Sept 2016

    Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the siteconf[curl] parameter, as demonstrated by a POST to news/comment.php containing PHP code, which is stored under db/comments/news/ and included by classes/index.php.

    Source:Kacper
    Published:6 Nov 2006
    5.1
    Medium

    CVE-2006-5730

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS 0.9.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_path parameter. NOTE: it is possible that this is a vulnerability in FCKeditor.

    Source:nuffsaid
    Published:6 Nov 2006
    4
    Medium

    CVE-2006-5728

    Last Modified: 27 Apr 2011

    XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long argument to the NLST command, possibly involving the -al flags.

    Source:boecke
    Published:6 Nov 2006
    5.1
    Medium

    CVE-2006-5727

    Last Modified: 28 Nov 2016

    PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arbitrary PHP code via the (1) _saz[settings][shippingfolder] and (2) _saz[settings][taxfolder] parameters.

    Source:IbnuSina
    Published:6 Nov 2006
    4.9
    Medium

    CVE-2006-5726

    Last Modified: 4 Nov 2017

    alloccgblk in the UFS filesystem in Solaris 10 allows local users to cause a denial of service (memory corruption) by mounting crafted UFS filesystems with malformed data structures.

    Source:LMH
    Published:6 Nov 2006
    5
    Medium

    CVE-2006-5725

    Last Modified: 23 Apr 2026

    The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request for a directory URI, which returns different HTTP status codes for existing and non-existing directories.

    Source:prdelka
    Published:4 Nov 2006
    5.1
    Medium

    CVE-2006-5722

    Last Modified: 19 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Segue CMS 1.5.9 and earlier, when magic_quotes_gpc is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the theme parameter to (1) themesettings.php or (2) index.php, a different vector than CVE-2006-5497. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:nuffsaid
    Published:4 Nov 2006
    4.9
    Medium

    CVE-2006-5721

    Last Modified: 14 Oct 2013

    The \Device\SandBox driver in Outpost Firewall PRO 4.0 (964.582.059) allows local users to cause a denial of service (system crash) via an invalid argument to the DeviceIoControl function that triggers an invalid memory operation.

    Source:Matousec Transparent security
    Published:4 Nov 2006
    7.5
    High

    CVE-2006-5720

    Last Modified: 12 Oct 2013

    SQL injection vulnerability in modules/journal/search.php in the Journal module in Francisco Burzi PHP-Nuke 7.9 and earlier allows remote attackers to execute arbitrary SQL commands via the forwhat parameter.

    Source:Paisterist
    Published:4 Nov 2006
    5
    Medium

    CVE-2006-5716

    Last Modified: 8 Dec 2016

    Directory traversal vulnerability in aff_news.php in FreeNews 2.1 allows remote attackers to include local files via a .. (dot dot) sequence in the chemin parameter, when the aff_news parameter is not set to "1."

    Source:MoHaNdKo
    Published:4 Nov 2006
    5
    Medium

    CVE-2006-5715

    Last Modified: 23 Apr 2026

    Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of an HTTP GET request, which accesses the alternate data stream.

    Source:Greg Linares
    Published:4 Nov 2006
    5
    Medium

    CVE-2006-5714

    Last Modified: 23 Apr 2026

    Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary files under the web root by appending "::$DATA" to the end of a HTTP GET request, which accesses the alternate data stream.

    Source:Greg Linares
    Published:4 Nov 2006
    4.3
    Medium

    CVE-2006-5712

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in Mirapoint WebMail allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated using the width style for an IMG element.

    Source:LegendaryZion
    Published:4 Nov 2006
    5
    Medium

    CVE-2006-5711

    Last Modified: 12 Oct 2013

    ECI Telecom B-FOCuS Wireless 802.11b/g ADSL2+ Router allows remote attackers to read arbitrary files via a certain HTTP request, as demonstrated by a request for a router configuration file, related to the /html/defs/ URI.

    Source:LegendaryZion
    Published:4 Nov 2006
    7.5
    High

    CVE-2006-5710

    Last Modified: 23 Apr 2026

    The Airport driver for certain Orinoco based Airport cards in Darwin kernel 8.8.0 in Apple Mac OS X 10.4.8, and possibly other versions, allows remote attackers to execute arbitrary code via an 802.11 probe response frame without any valid information element (IE) fields after the header, which triggers a heap-based buffer overflow.

    Source:H D Moore
    Published:4 Nov 2006
    7.5
    High

    CVE-2006-5707

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:ajann
    Published:4 Nov 2006
    4.3
    Medium

    CVE-2006-5703

    Last Modified: 18 Oct 2016

    Cross-site scripting (XSS) vulnerability in tiki-featured_link.php in Tikiwiki 1.9.5 allows remote attackers to inject arbitrary web script or HTML via a url parameter that evades filtering, as demonstrated by a parameter value containing malformed, nested SCRIPT elements.

    Source:securfrog
    Published:4 Nov 2006
    5
    Medium

    CVE-2006-5702

    Last Modified: 18 Oct 2016

    Tikiwiki 1.9.5 allows remote attackers to obtain sensitive information (MySQL username and password) via an empty sort_mode parameter in (1) tiki-listpages.php, (2) tiki-lastchanges.php, (3) messu-archive.php, (4) messu-mailbox.php, (5) messu-sent.php, (6) tiki-directory_add_site.php, (7) tiki-directory_ranking.php, (8) tiki-directory_search.php, (9) tiki-forums.php, (10) tiki-view_forum.php, (11) tiki-friends.php, (12) tiki-list_blogs.php, (13) tiki-list_faqs.php, (14) tiki-list_trackers.php, (15) tiki-list_users.php, (16) tiki-my_tiki.php, (17) tiki-notepad_list.php, (18) tiki-orphan_pages.php, (19) tiki-shoutbox.php, (20) tiki-usermenu.php, and (21) tiki-webmail_contacts.php, which reveal the information in certain database error messages.

    Source:securfrog
    Published:4 Nov 2006
    4.9
    Medium

    CVE-2006-5701

    Last Modified: 14 Oct 2013

    Double free vulnerability in squashfs module in the Linux kernel 2.6.x, as used in Fedora Core 5 and possibly other distributions, allows local users to cause a denial of service by mounting a crafted squashfs filesystem.

    Source:LMH
    Published:3 Nov 2006
    6.4
    Medium

    CVE-2006-5676

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the champ parameter.

    Source:ajann
    Published:3 Nov 2006
    10
    Critical

    CVE-2006-5675

    Last Modified: 23 Apr 2026

    Multiple unspecified vulnerabilities in Pentaho Business Intelligence (BI) Suite before 1.2 RC3 (1.2.0.470-RC3) have unknown impact and attack vectors, related to "MySQL Scripts need changes for security," possibly SQL injection vulnerabilities associated with these scripts.

    Source:antisnatchor
    Published:3 Nov 2006
    6.8
    Medium

    CVE-2006-5673

    Last Modified: 24 Nov 2016

    PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pathToFiles parameter.

    Source:Kacper
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5672

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the INCLUDE_PATH parameter.

    Source:Kacper
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5670

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AD_BODY_TEMP parameter.

    Source:Kacper
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5669

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions before 1.4.4, allows remote attackers to execute arbitrary PHP code via a URL in the filename parameter.

    Source:Sumit Siddharth
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5667

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the pb_lang parameter to (1) admin.php and (2) pbook.php.

    Source:Matdhule
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5666

    Last Modified: 1 Nov 2017

    SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL commands via the login parameter. NOTE: some of these details are obtained from third party information.

    Source:ajann
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5665

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Kacper
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5662

    Last Modified: 12 Oct 2013

    SQL injection vulnerability in easy notesManager (eNM) 0.0.1 allows remote attackers to execute arbitrary SQL commands via (1) the username parameter in login.php and (2) a search on the "search page."

    Source:poplix
    Published:3 Nov 2006
    6.8
    Medium

    CVE-2006-5661

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in nquser.php in VIRtech Netquery allows remote attackers to inject arbitrary web script or HTML via the User-Agent HTTP header.

    Source:Tal Argoni
    Published:3 Nov 2006
    4.3
    Medium

    CVE-2006-5653

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in the errorHTML function in the index script in Sun Java System Messenger Express 6 allows remote attackers to inject arbitrary web script or HTML via the error parameter. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers a new CVE was assigned.

    Source:Handrix
    Published:3 Nov 2006
    4.3
    Medium

    CVE-2006-5652

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in Sun iPlanet Messaging Server Messenger Express allows remote attackers to inject arbitrary web script via the expression Cascading Style Sheets (CSS) function, as demonstrated by setting the width style for an IMG element. NOTE: this issue might be related to CVE-2006-5486, however due to the vagueness of the initial advisory and different researchers, it has been assigned a new CVE.

    Source:LegendaryZion
    Published:3 Nov 2006
    7.5
    High

    CVE-2006-5650

    Last Modified: 10 Mar 2011

    The ICQPhone.SipxPhoneManager ActiveX control in America Online ICQ 5.1 allows remote attackers to download and execute arbitrary code via the DownloadAgent function, as demonstrated using an ICQ avatar.

    Source:Metasploit
    Published:7 Nov 2006
    6.4
    Medium

    CVE-2006-5647

    Last Modified: 14 Aug 2017

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a malformed CHM file with a large name length in the CHM chunk header, aka "CHM name length memory consumption vulnerability."

    Source:Damian Put
    Published:1 Nov 2006
    5
    Medium

    CVE-2006-5646

    Last Modified: 16 Sept 2016

    Heap-based buffer overflow in Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when archive scanning is enabled, allows remote attackers to trigger a denial of service (memory corruption) via a CHM file with an LZX decompression header that specifies a Window_size of 0.

    Source:Damian Put
    Published:1 Nov 2006
    5
    Medium

    CVE-2006-5645

    Last Modified: 16 Sept 2016

    Sophos Anti-Virus and Endpoint Security before 6.0.5, Anti-Virus for Linux before 5.0.10, and other platforms before 4.11, when "Enabled scanning of archives" is set, allows remote attackers to cause a denial of service (infinite loop) via a malformed RAR archive with an Archive Header section with the head_size and pack_size fields set to zero.

    Source:Damian Put
    Published:1 Nov 2006
    6.8
    Medium

    CVE-2006-5643

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in search_de.html in foresite CMS allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:David Vieira-Kurz
    Published:1 Nov 2006
    7.5
    High

    CVE-2006-5641

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:ajann
    Published:1 Nov 2006
    7.5
    High

    CVE-2006-5640

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:ajann
    Published:1 Nov 2006
    7.5
    High

    CVE-2006-5638

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) limite and (2) mots parameters.

    Source:ajann
    Published:1 Nov 2006
    7.5
    High

    CVE-2006-5637

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute arbitrary PHP code via a URL in the email parameter.

    Source:v1per-haCker
    Published:1 Nov 2006
    5.1
    Medium

    CVE-2006-5636

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SWSDIR parameter.

    Source:Mehmet Ince
    Published:1 Nov 2006
    7.5
    High

    CVE-2006-5635

    Last Modified: 11 Oct 2013

    SQL injection vulnerability in forum/search.asp in Web Wiz Forums allows remote attackers to execute arbitrary SQL commands via the KW parameter.

    Source:almaster
    Published:1 Nov 2006
    6.8
    Medium

    CVE-2006-5634

    Last Modified: 14 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) reqpath parameter to (a) body.inc.php and (b) body_blog.inc.php in users/include/; or the (2) usrinc parameter in users/include/upload_ht.inc.php.

    Source:v1per-haCker
    Published:1 Nov 2006
    5
    Medium

    CVE-2006-5633

    Last Modified: 23 Apr 2026

    Firefox 1.5.0.7 and 2.0, and Seamonkey 1.1b, allows remote attackers to cause a denial of service (crash) by creating a range object using createRange, calling selectNode on a DocType node (DOCUMENT_TYPE_NODE), then calling createContextualFragment on the range, which triggers a null dereference. NOTE: the original Bugtraq post mentioned that code execution was possible, but followup analysis has shown that it is only a null dereference.

    Source:Gotfault Security
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5629

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Hosting Controller 6.1 before Hotfix 3.3 allow remote attackers to execute arbitrary SQL commands via the ForumID parameter in (1) DisableForum.asp and (2) enableForum.asp. NOTE: it was later reported that the vulnerability is present in 6.1 Hotfix 3.3 and earlier.

    Source:Soroush Dalili
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5627

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the adminfolderpath parameter to (1) headerscripts.php, (2) footerhome.php, and (3) footermain.php in admin/include/; (4) photogallery/headerscripts.php; and (5) footerhome.php, (6) footermain.php, (7) headermain.php, (8) sitemapfooter.php, and (9) sitemapheader.php in templates/.

    Source:K-159
    Published:31 Oct 2006
    4.3
    Medium

    CVE-2006-5626

    Last Modified: 12 Oct 2013

    Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.

    Source:Vigilon
    Published:31 Oct 2006