5.1
    Medium

    CVE-2006-5625

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Management System (WCMS) 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c[path] parameter.

    Source:Kacper
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5624

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Multi-Page Comment System (MPCS) 1.0.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) include.php or (2) functions.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:v1per-haCker
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5623

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cgipath parameter.

    Source:Mehmet Ince
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5622

    Last Modified: 14 Sept 2016

    SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary SQL commands via the aid parameter.

    Source:w4ck1ng
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5621

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote attackers to execute arbitrary PHP code via a URL in the footfile parameter.

    Source:v1per-haCker
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5620

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[page_dir] parameter, a different vector than CVE-2006-4489.

    Source:Mehmet Ince
    Published:31 Oct 2006
    5
    Medium

    CVE-2006-5618

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in script/cat_for_aff.php in Netref 4 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the ad_direct parameter.

    Source:ajann
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5615

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in publish.php in Textpattern 1.19, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the txpcfg[txpath] parameter.

    Source:Bithedz
    Published:31 Oct 2006
    2.6
    Low

    CVE-2006-5614

    Last Modified: 14 Nov 2016

    Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, allows remote attackers to cause a denial of service (svchost.exe crash) via a malformed DNS query, which results in a null pointer dereference.

    Source:h07
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5613

    Last Modified: 23 Apr 2026

    PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the fullpath parameter

    Source:Mehmet Ince
    Published:31 Oct 2006
    7.5
    High

    CVE-2006-5612

    Last Modified: 26 Sept 2016

    PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the aide parameter.

    Source:Dj7xpl
    Published:31 Oct 2006
    5
    Medium

    CVE-2006-5609

    Last Modified: 11 Oct 2013

    Directory traversal vulnerability in dir.php in TorrentFlux 2.1 allows remote attackers to list arbitrary directories via "\.\./" sequences in the dir parameter.

    Source:Christopher
    Published:30 Oct 2006
    9.8
    Critical

    CVE-2006-5603

    Last Modified: 11 Oct 2013

    SQL injection vulnerability in pop_mail.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL commands via the RC parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Arham Muhammad
    Published:30 Oct 2006
    7.5
    High

    CVE-2006-5597

    Last Modified: 23 Apr 2026

    join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accounts via modified (1) frmMailBox and (2) frmUserPass parameters.

    Source:Greg Linares
    Published:28 Oct 2006
    7.5
    High

    CVE-2006-5596

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary files via ..\ (dot dot backslash) sequences in an HTTP GET request.

    Source:prdelka
    Published:28 Oct 2006
    7.5
    High

    CVE-2006-5590

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in ArticleBeach Script 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Bithedz
    Published:27 Oct 2006
    7.5
    High

    CVE-2006-5588

    Last Modified: 28 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and magic_quotes_gpc are enabled, allow remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter to (1) includes/rss-reader.php or (2) admin/config.php, different vectors than CVE-2006-3185.

    Source:r0ut3r
    Published:27 Oct 2006
    7.5
    High

    CVE-2006-5587

    Last Modified: 14 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in MDweb 1.3 and earlier (Mdweb132-postgres) allow remote attackers to execute arbitrary PHP code via a URL in the chemin_appli parameter in (1) admin/inc/organisations/form_org.inc.php and (2) admin/inc/organisations/country_insert.php.

    Source:Drago84
    Published:27 Oct 2006
    7.2
    High

    CVE-2006-5586

    Last Modified: 27 Oct 2016

    The Graphics Rendering Engine in Microsoft Windows 2000 SP4 and XP SP2 allows local users to gain privileges via "invalid application window sizes" in layered application windows, aka the "GDI Invalid Window Size Elevation of Privilege Vulnerability."

    Source:Ivanlef0u
    Published:4 Apr 2007
    7.5
    High

    CVE-2006-5571

    Last Modified: 10 Oct 2013

    Stack-based buffer overflow in /scripts/cruise/cws.exe in CruiseWorks 1.09c and 1.09d allows remote attackers to execute arbitrary code via a long string in the doc parameter.

    Source:Tan Chew Keong
    Published:27 Oct 2006
    5
    Medium

    CVE-2006-5568

    Last Modified: 11 Oct 2013

    FtpXQ Server 3.0.1 allows remote attackers to cause a denial of service (CPU exhaustion) via a long MKD command.

    Source:Federico Fazzi
    Published:27 Oct 2006
    9.3
    Critical

    CVE-2006-5567

    Last Modified: 14 Sept 2016

    Multiple heap-based buffer overflows in AOL Nullsoft WinAmp before 5.31 allow user-assisted remote attackers to execute arbitrary code via a crafted (1) ultravox-max-msg header to the Ultravox protocol handler or (2) unspecified Lyrics3 tags.

    Source:cocoruder
    Published:27 Oct 2006
    5
    Medium

    CVE-2006-5566

    Last Modified: 10 Oct 2013

    CRLF injection vulnerability in premium/index.php in Shop-Script allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via CRLF sequences in the (1) links_exchange, (2) news, (3) search_with_change_category_ability, (4) logging, (5) feedback, (6) show_price, (7) register, (8) answer, (9) productID, and (10) inside parameters.

    Source:Debasis Mohanty
    Published:27 Oct 2006
    4.3
    Medium

    CVE-2006-5564

    Last Modified: 11 Oct 2013

    Cross-site scripting (XSS) vulnerability in user.php in MAXdev MD-Pro 1.0.76 allows remote attackers to inject arbitrary web script or HTML via the op parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:r00t
    Published:27 Oct 2006
    7.5
    High

    CVE-2006-5562

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote attackers to execute arbitrary PHP code via the sys_dbtype parameter.

    Source:Kw3[R]Ln
    Published:27 Oct 2006
    7.5
    High

    CVE-2006-5561

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL commands via the cdb_auth cookie.

    Source:rgod
    Published:27 Oct 2006
    9.3
    Critical

    CVE-2006-5559

    Last Modified: 14 Sept 2016

    The Execute method in the ADODB.Connection 2.7 and 2.8 ActiveX control objects (ADODB.Connection.2.7 and ADODB.Connection.2.8) in the Microsoft Data Access Components (MDAC) 2.5 SP3, 2.7 SP1, 2.8, and 2.8 SP1 does not properly track freed memory when the second argument is a BSTR, which allows remote attackers to cause a denial of service (Internet Explorer crash) and possibly execute arbitrary code via certain strings in the second and third arguments.

    Source:YAG KOHHA
    Published:27 Oct 2006
    10
    Critical

    CVE-2006-5558

    Last Modified: 23 Apr 2026

    Format string vulnerability in the swask command in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via format string specifiers in the -s argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

    Source:prdelka
    Published:27 Oct 2006
    4.6
    Medium

    CVE-2006-5557

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long -S argument. NOTE: this might be a duplicate of CVE-2006-2574, but the details relating to CVE-2006-2574 are too vague to be certain.

    Source:prdelka
    Published:27 Oct 2006
    4.6
    Medium

    CVE-2006-5556

    Last Modified: 23 Apr 2026

    Buffer overflow in the localtime_r function, and certain other functions, in libc in HP-UX B.11.11 and possibly other versions allows local users to execute arbitrary code via a long TZ environment variable.

    Source:prdelka
    Published:27 Oct 2006
    7.5
    High

    CVE-2006-5555

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execute arbitrary PHP code via the langage parameter.

    Source:Kw3[R]Ln
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5554

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local files via a .. (dot dot) in the user_settings cookie, as demonstrated by using the MyFile parameter in albumview.php to upload a text/plain .gif file containing PHP code, which is executed by index.php.

    Source:Kacper
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5552

    Last Modified: 23 Apr 2026

    Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of service (CPU consumption or application crash) or execute arbitrary code via a long argument to the (1) MAIL FROM or (2) RCPT TO command.

    Source:Greg Linares
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5551

    Last Modified: 14 Sept 2016

    Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a long argument to the RCPT TO command.

    Source:Greg Linares
    Published:26 Oct 2006
    4.9
    Medium

    CVE-2006-5550

    Last Modified: 4 Oct 2017

    The kernel in FreeBSD 6.1 and OpenBSD 4.0 allows local users to cause a denial of service via unspecified vectors involving certain ioctl requests to /dev/crypto.

    Source:Evgeny Legerov
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5548

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0.0 through 2.1.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][directories][classes] parameter.

    Source:GregStar
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5547

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0.0 through 1.0.3 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][includes] parameter.

    Source:GregStar
    Published:26 Oct 2006
    5.1
    Medium

    CVE-2006-5546

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3.0 through 1.4.1 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[config][otscms][directories][classes] parameter.

    Source:GregStar
    Published:26 Oct 2006
    5.1
    Medium

    CVE-2006-5543

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:Mehmet Ince
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5539

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg[homepath] parameter.

    Source:Mehmet Ince
    Published:26 Oct 2006
    5
    Medium

    CVE-2006-5536

    Last Modified: 10 Oct 2013

    Directory traversal vulnerability in cgi-bin/webcm in D-Link DSL-G624T firmware 3.00B01T01.YA-C.20060616 allows remote attackers to read arbitrary files via a .. (dot dot) in the getpage parameter.

    Source:jose.palanco
    Published:26 Oct 2006
    4.3
    Medium

    CVE-2006-5535

    Last Modified: 23 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in WebHostManager (WHM) 10.8.0 cPanel 10.9.0 R50 allow remote attackers to inject arbitrary web script or HTML via the (1) theme parameter to scripts/dosetmytheme and the (2) template parameter to scripts2/editzonetemplate.

    Source:Crackers_Child
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5531

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in embedded.php in Ascended Guestbook 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[path] parameter.

    Source:Kacper
    Published:26 Oct 2006
    4.3
    Medium

    CVE-2006-5530

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Boesch SimpNews before 2.34.01 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters to (1) admin/index.php, (2) admin/pwlost.php, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Published:26 Oct 2006
    5.1
    Medium

    CVE-2006-5529

    Last Modified: 10 Oct 2013

    Cross-site scripting (XSS) vulnerability in smumdadotcom_ascyb_alumni/mod.php in SchoolAlumni Portal 2.26 allows remote attackers to inject arbitrary web script or HTML via the query parameter in a search operation in the katalog module. NOTE: some of these details are obtained from third party information.

    Source:MP
    Published:26 Oct 2006
    5
    Medium

    CVE-2006-5528

    Last Modified: 10 Oct 2013

    Directory traversal vulnerability in mod.php in SchoolAlumni Portal 2.26 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the mod parameter. NOTE: some of these details are obtained from third party information.

    Source:MP
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5527

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib.editor.inc.php in Intelimen InteliEditor 1.2.x allows remote attackers to execute arbitrary PHP code via a URL in the sys_path parameter.

    Source:Mehmet Ince
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5526

    Last Modified: 14 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 2021.4.40 and earlier, allow remote attackers to execute arbitrary PHP code via a URL in the foing_root_path parameter in (a) faq.php, (b) index.php, (c) list.php, (d) login.php, (e) playlist.php, (f) song.php, (g) gen_m3u.php, (h) view_artist.php, (i) view_song.php, (j) flash/set_na.php, (k) flash/initialise.php, (l) flash/get_song.php, (m) includes/common.php, (n) admin/nav.php, (o) admin/main.php, (p) admin/list_artists.php, (q) admin/index.php, (r) admin/genres.php, (s) admin/edit_artist.php, (t) admin/edit_album.php, (u) admin/config.php, and (v) admin/admin_status.php in player/, different vectors than CVE-2006-3045. NOTE: CVE analysis as of 20061026 indicates that files in the admin/ and flash/ directories define foing_root_path before use.

    Source:020
    Published:26 Oct 2006
    5.1
    Medium

    CVE-2006-5525

    Last Modified: 12 Sept 2016

    Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL injection attacks via (1) "/**/UNION " or (2) " UNION/**/" sequences, which are not rejected by the protection mechanism, as demonstrated by a SQL injection via the eid parameter in a search action in the Encyclopedia module in modules.php.

    Source:Paisterist
    Published:26 Oct 2006
    6.8
    Medium

    CVE-2006-5524

    Last Modified: 24 Jan 2017

    Cross-site scripting (XSS) vulnerability in index.php in phplist 2.10.2 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: This issue might overlap CVE-2006-5321.

    Source:b0rizQ
    Published:26 Oct 2006