7.5
    High

    CVE-2006-5523

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in common.php in EZ-Ticket 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the ezt_root_path parameter.

    Source:the master
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5522

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Johannes Erdfelt Kawf 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the config parameter in (1) main.php or (2) user/account/main.php.

    Source:o0xxdark0o
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5521

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.

    Source:Drago84
    Published:26 Oct 2006
    6.8
    Medium

    CVE-2006-5519

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:h4ntu
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5518

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) xml2rss.php, (2) config_local.php, (3) rssonate.php, and (4) sql2xml.php in Src/getFeed/inc/.

    Source:Kw3[R]Ln
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5517

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote attackers to execute arbitrary PHP code via a URL in the PROJECT_ROOT parameter to (1) editmeetings/session.php, (2) email/session.php, (3) entityproperties/session.php, or (4) inc/mail.php.

    Source:Mehmet Ince
    Published:26 Oct 2006
    4.3
    Medium

    CVE-2006-5516

    Last Modified: 10 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php.

    Source:Raphael Huck
    Published:26 Oct 2006
    7.5
    High

    CVE-2006-5514

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in quiz.php in Web Group Communication Center (WGCC) 0.5.6b and earlier allows remote attackers to execute arbitrary SQL commands via the qzid parameter.

    Source:ajann
    Published:26 Oct 2006
    4.3
    Medium

    CVE-2006-5512

    Last Modified: 10 Oct 2013

    Cross-site scripting (XSS) vulnerability in article.htm in Zwahlen Online Shop allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:Crackers_Child
    Published:25 Oct 2006
    2.6
    Low

    CVE-2006-5511

    Last Modified: 8 Dec 2016

    Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, allows remote attackers to inject arbitrary web script, HTML, or PHP via the contents parameter, whose value is prepended to the file specified by the forum parameter.

    Source:Kacper
    Published:25 Oct 2006
    6.4
    Medium

    CVE-2006-5510

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbitrary local files via ".." sequences in the Language cookie, as demonstrated by uploading a .gif file that contains PHP code.

    Source:Kacper
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5509

    Last Modified: 23 Apr 2026

    Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary PHP code via crafted POST requests that store PHP code in a database that is later processed by eval, as demonstrated using SQL injection via the n parameter.

    Source:ShAnKaR
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5508

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute arbitrary SQL commands via (1) the n parameter and (2) the User-Agent HTTP header.

    Source:ShAnKaR
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5506

    Last Modified: 14 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in WiClear 0.10 allow remote attackers to execute arbitrary PHP code via the path parameter in (1) inc/prepend.inc.php, (2) inc/lib/boxes.lib.php, (3) inc/lib/tools.lib.php, (4) tools/trackback/index.php, and (5) tools/utf8conversion/index.php in admin/; and (6) prepend.inc.php, (7) lib/boxes.lib.php, and (8) lib/history.lib.php in inc/.

    Source:the master
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5505

    Last Modified: 23 Apr 2026

    Multiple PHP file inclusion vulnerabilities in 2BGal 3.0 allow remote attackers to execute arbitrary PHP code via the lang parameter to (1) admin/configuration.inc.php, (2) admin/creer_album.inc.php, (3) admin/changepwd.php.inc, and unspecified other files. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Kw3[R]Ln
    Published:25 Oct 2006
    4.3
    Medium

    CVE-2006-5503

    Last Modified: 9 Dec 2016

    Cross-site scripting (XSS) vulnerability in index.php in Simple Machines Forum (SMF) 1.1 RC2 allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Source:b0rizQ
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5497

    Last Modified: 19 Oct 2017

    PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the themesdir parameter.

    Source:nuffsaid
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5495

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_red2 parameter to (a) _msdazu_pdata/redaktion/artikel/up/index.php; (b) addtort.php, (c) colorpik2.php, (d) colorpik3.php, (e) extras_menu.php, (f) farbpalette.php, (g) lese_inc.php, and (h) newfile.php in _msdazu_share/richtext/; the (2) path_scr_dat2 parameter to (i)_msdazu_share/share/insert1.php; the (3) path_red parameter to (j) _msdazu_share/extras/downloads/index.php; and unspecified parameters in other files.

    Source:k1tk4t
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5494

    Last Modified: 19 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB module for PHP-Nuke allow remote attackers to execute arbitrary PHP code via a URL in the (1) adminpath or (2) basepath parameters. NOTE: this issue might overlap CVE-2006-6795.

    Source:nukedclx
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5493

    Last Modified: 8 Nov 2016

    PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:SHiKaA
    Published:25 Oct 2006
    7.5
    High

    CVE-2006-5485

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SpeedBerg 1.2beta1 allow remote attackers to execute arbitrary PHP code via a URL in the SPEEDBERG_PATH parameter to (1) entrancePage.tpl.php, (2) generalToolBox.tlb.php, (3) myToolBox.tlb.php, (4) scriplet.inc.php, (5) simplePage.tpl.php, (6) speedberg.class.php, and (7) standardPage.tpl.php.

    Source:k1tk4t
    Published:24 Oct 2006
    2.1
    Low

    CVE-2006-5483

    Last Modified: 13 Oct 2017

    p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, which should only be settable by root.

    Source:kokanin
    Published:24 Oct 2006
    2.1
    Low

    CVE-2006-5482

    Last Modified: 13 Oct 2017

    ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate function on a file type that is not VREG, VLNK or VDIR, which is not defined in POSIX.

    Source:kokanin
    Published:24 Oct 2006
    5.1
    Medium

    CVE-2006-5480

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in lib/rs.php in 2le.net Castor PHP Web Builder 1.1.1 allows remote attackers to execute arbitrary PHP code via the rootpath parameter.

    Source:Kw3[R]Ln
    Published:24 Oct 2006
    7.5
    High

    CVE-2006-5478

    Last Modified: 10 Oct 2013

    Multiple stack-based buffer overflows in Novell eDirectory 8.8.x before 8.8.1 FTF1, and 8.x up to 8.7.3.8, and Novell NetMail before 3.52e FTF2, allow remote attackers to execute arbitrary code via (1) a long HTTP Host header, which triggers an overflow in the BuildRedirectURL function; or vectors related to a username containing a . (dot) character in the (2) SMTP, (3) POP, (4) IMAP, (5) HTTP, or (6) Networked Messaging Application Protocol (NMAP) Netmail services.

    Source:Manuel Santamarina Suarez
    Published:24 Oct 2006
    7.5
    High

    CVE-2006-5472

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter in (1) lib/registry.lib.php, (2) lib/sqlcompose.lib.php, and (3) lib/sqlsearch.lib.php.

    Source:MP
    Published:24 Oct 2006
    7.5
    High

    CVE-2006-5471

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the (1) cfg_dir and (2) lib_dir parameters.

    Source:k1tk4t
    Published:24 Oct 2006
    7.5
    High

    CVE-2006-5458

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common.php in Hinton Design phpht Topsites allows remote attackers to execute arbitrary PHP code via a URL in the phpht_real_path parameter.

    Source:Mehmet Ince
    Published:23 Oct 2006
    7.5
    High

    CVE-2006-5450

    Last Modified: 9 Oct 2013

    SQL injection vulnerability in index.asp in Kinesis Interactive Cinema System (KICS) CMS allows remote attackers to execute arbitrary SQL commands via the (1) txtUsername (user) or (2) txtPassword (pass) parameters.

    Source:fireboy
    Published:23 Oct 2006
    5.1
    Medium

    CVE-2006-5446

    Last Modified: 10 Oct 2013

    SQL injection vulnerability in lobby/config.php in Casinosoft Casino Script (aka Masvet) 3.2 allows remote attackers to execute arbitrary SQL commands via the cfam parameter.

    Source:G1UK
    Published:23 Oct 2006
    7.5
    High

    CVE-2006-5444

    Last Modified: 23 Apr 2026

    Integer overflow in the get_input function in the Skinny channel driver (chan_skinny.c) in Asterisk 1.0.x before 1.0.12 and 1.2.x before 1.2.13, as used by Cisco SCCP phones, allows remote attackers to execute arbitrary code via a certain dlen value that passes a signed integer comparison and leads to a heap-based buffer overflow.

    Source:Noam Rathaus
    Published:23 Oct 2006
    7.5
    High

    CVE-2006-5436

    Last Modified: 9 Oct 2013

    PHP remote file inclusion vulnerability in index.php in FreeFAQ 1.0.e allows remote attackers to execute arbitrary PHP code via a URL in the faqpath parameter.

    Source:Alireza Ahari
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5434

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitrary PHP code via a URL in the pn_lang parameter.

    Source:vegas78
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5433

    Last Modified: 17 Oct 2017

    PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[local_root] parameter.

    Source:nuffsaid
    Published:20 Oct 2006
    2.6
    Low

    CVE-2006-5432

    Last Modified: 14 Nov 2016

    Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is enabled, allow remote attackers to create or overwrite arbitrary files via the (1) email[to], (2) email[from], (3) name[to], (4) name[from], (5) picture, (6) comment, or (7) sessionID parameter, as demonstrated by creating a new .php file that permits remote file inclusion, and then requesting this file.

    Source:nuffsaid
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5431

    Last Modified: 9 Oct 2013

    PHP remote file inclusion vulnerability in gorum/dbproperty.php in PHPOutsourcing Zorum 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appDirName parameter.

    Source:MoHaNdKo
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5429

    Last Modified: 17 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the renderer parameter in template.tpl.php in (1) templates/barrel/, (2) templates/sidebar/, (3) templates/text-only, (4) templates/slashdot/, (5) templates/penguin/, (6) templates/pda/, (7) templates/oerdec/, (8) templates/nifty/, (9) templates/mylook, and (10) templates/barry/.

    Source:mdx
    Published:20 Oct 2006
    5
    Medium

    CVE-2006-5428

    Last Modified: 9 Oct 2013

    rpc.php in Cerberus Helpdesk 3.2.1 does not verify a client's privileges for a display_get_requesters operation, which allows remote attackers to bypass the GUI login and obtain sensitive information (ticket data) via a direct request.

    Source:jonepet
    Published:20 Oct 2006
    5.1
    Medium

    CVE-2006-5427

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in plugins/main.php in Php AMX 0.9.0, when register_globals is enabled or magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plug_path parameter.

    Source:MP
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5426

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbitrary PHP code via a URL in the LIBDIR parameter.

    Source:o0xxdark0o
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5423

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_module.php in Lou Portail 1.4.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the g_admin_rep parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:MP
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5422

    Last Modified: 9 Oct 2013

    PHP remote file inclusion vulnerability in calcul-page.php in Lodel (patchlodel) 0.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the home parameter.

    Source:The_BeKiR
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5421

    Last Modified: 23 Apr 2026

    WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoconfig parameter that points to an avatar image that contains PHP code, which is then accessed from prestart.php. NOTE: this issue has been labeled remote file inclusion, but that label only applies to the attack, not the underlying vulnerability.

    Source:Kacper
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5419

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the dir parameter.

    Source:Kw3[R]Ln
    Published:20 Oct 2006
    6.8
    Medium

    CVE-2006-5418

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in archive/archive_topic.php in pbpbb archive for search engines (SearchIndexer) (aka phpBBSEI) for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5415

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_newshr.php in the News Defilante Horizontale 4.1.1 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5413

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute arbitrary PHP code via a URL in the sourcedir parameter to (1) Offline.php, (2) Sources/Admin.php, (3) Sources/Offline.php, or (4) content/portalshow.php.

    Source:SilenZ
    Published:20 Oct 2006
    5.1
    Medium

    CVE-2006-5412

    Last Modified: 23 Apr 2026

    admin.php in PHP Outburst Easynews 4.4.1 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication, and gain the ability to execute arbitrary code, via the en_login_id parameter.

    Source:nuffsaid
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5411

    Last Modified: 12 Oct 2017

    Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier, allows remote attackers to upload and execute arbitrary PHP programs.

    Source:HACKERS PAL
    Published:20 Oct 2006
    7.5
    High

    CVE-2006-5402

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPmybibli 3.0.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) class_path, (2) javascript_path, and (3) include_path parameters in (a) cart.php; the (4) class_path parameter in (b) index.php; the (5) javascript_path parameter in (c) edit.php; the (6) include_path parameter in (d) circ.php; unspecified parameters in (e) select.php; and unspecified parameters in other files.

    Source:the_day
    Published:18 Oct 2006