7.5
    High

    CVE-2006-5401

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in template/barnraiser_01/p_new_password.tpl.php in AROUNDMe 0.5.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatePath parameter.

    Source:Kw3[R]Ln
    Published:18 Oct 2006
    5.1
    Medium

    CVE-2006-5400

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:Kw3[R]Ln
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5399

    Last Modified: 17 Oct 2017

    PHP remote file inclusion vulnerability in classes/Import_MM.class.php in PHPRecipeBook 2.36, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the g_rb_basedir parameter.

    Source:r0ut3r
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5398

    Last Modified: 16 Oct 2017

    SQL injection vulnerability in comments.php in Simplog 0.9.3.1 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:w4ck1ng
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5395

    Last Modified: 9 Oct 2013

    Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute arbitrary code via a long string. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:mmd_000
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5392

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenDock FullCore 4.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) sw/index_sw.php; (2) cart.php, (3) lib_cart.php, (4) lib_read_cart.php, (5) lib_sys_cart.php, and (6) txt_info_cart.php in sw/lib_cart/; (7) comment.php, (8) find_comment.php, and (9) lib_comment.php in sw/lib_comment/; (10) sw/lib_find/find.php; and other unspecified PHP scripts.

    Source:Matdhule
    Published:18 Oct 2006
    5
    Medium

    CVE-2006-5391

    Last Modified: 23 Apr 2026

    Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string to UDP port 25777.

    Source:n00b
    Published:18 Oct 2006
    6.8
    Medium

    CVE-2006-5390

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:bd0rk
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5388

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQL commands via the getsquad parameter, a different vector than CVE-2006-4783.

    Source:Kiba
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5387

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5386

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the DEFAULT_SKIN parameter.

    Source:Kw3[R]Ln
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5385

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5384

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the AGE parameter.

    Source:Drago84
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5383

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in comadd.php in Def-Blog 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the article parameter.

    Source:SHiKaA
    Published:18 Oct 2006
    7.5
    High

    CVE-2006-5379

    Last Modified: 23 Apr 2026

    The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762, and probably on other operating systems, allows local and remote attackers to execute arbitrary code via a large width value in a font glyph, which can be used to overwrite arbitrary memory locations.

    Source:Rapid7 Security
    Published:18 Oct 2006
    5
    Medium

    CVE-2006-5320

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in getimg.php in Album Photo Sans Nom 1.6 allows remote attackers to read arbitrary files via the img parameter.

    Source:DarkFig
    Published:17 Oct 2006
    5
    Medium

    CVE-2006-5319

    Last Modified: 12 Sept 2016

    Directory traversal vulnerability in redir.php in Foafgen 0.3 allows remote attackers to read arbitrary files via a .. (dot dot) in the foaf parameter.

    Source:DarkFig
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5318

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execute arbitrary PHP code via an FTP URL in the section parameter.

    Source:DarkFig
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5317

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in eboli allows remote attackers to execute arbitrary PHP code via a URL in the contentSpecial parameter.

    Source:DarkFig
    Published:17 Oct 2006
    7.8
    High

    CVE-2006-5316

    Last Modified: 23 Apr 2026

    registroTL stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for /usuarios.dat.

    Source:DarkFig
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5315

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in main.php in registroTL allows remote attackers to execute arbitrary PHP code via an ftp:// URL in the page parameter.

    Source:DarkFig
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5314

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ftag.php in TribunaLibre 3.12 Beta allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.

    Source:DarkFig
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5312

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:boecke
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5311

    Last Modified: 8 Oct 2013

    PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in Buzlas 2006-1 Full allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:17 Oct 2006
    6.8
    Medium

    CVE-2006-5310

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in common/visiteurs/include/menus.inc.php in J-Pierre DEZELUS Les Visiteurs 2.0.1, as used in phpMyConferences (phpMyConference) 8.0.2 and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the lvc_include_dir parameter.

    Source:k1tk4t
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5309

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5308

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers to execute arbitrary PHP code via a URL in the fullpath parameter in (1) include/theme.inc.php or (2) include/footer.inc.php.

    Source:k1tk4t
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5307

    Last Modified: 12 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP code via a URL in the Htmls parameter in (1) add.php, (2) admin.php, (3) look.php, or (4) re.php.

    Source:mdx
    Published:17 Oct 2006
    6.8
    Medium

    CVE-2006-5306

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/journals_delete.php, (2) includes/journals_post.php, or (3) includes/journals_edit.php.

    Source:Nima Salehi
    Published:17 Oct 2006
    5.1
    Medium

    CVE-2006-5305

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5304

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.

    Source:Kacper
    Published:17 Oct 2006
    7.5
    High

    CVE-2006-5302

    Last Modified: 12 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrary PHP code via a URL in the (1) lang_prefix parameter to (a) conn.php, (b) sesscheck.php, (c) wap/conn.php, or (d) wap/sesscheck.php, or the (2) lang parameter to (e) index.php.

    Source:r0ut3r
    Published:17 Oct 2006
    6.8
    Medium

    CVE-2006-5301

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Nima Salehi
    Published:17 Oct 2006
    4.3
    Medium

    CVE-2006-5296

    Last Modified: 27 Oct 2016

    PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record length, which allows user-assisted attackers to cause a denial of service (NULL dereference and application crash) via a crafted PowerPoint (.PPT) file, as demonstrated by Nanika.ppt, and a different vulnerability than CVE-2006-3435, CVE-2006-3876, CVE-2006-3877, and CVE-2006-4694. NOTE: the impact of this issue was originally claimed to be arbitrary code execution, but later analysis demonstrated that this was erroneous.

    Source:Nanika
    Published:16 Oct 2006
    5
    Medium

    CVE-2006-5295

    Last Modified: 12 Sept 2016

    Unspecified vulnerability in ClamAV before 0.88.5 allows remote attackers to cause a denial of service (scanning service crash) via a crafted Compressed HTML Help (CHM) file that causes ClamAV to "read an invalid memory location."

    Source:Damian Put
    Published:16 Oct 2006
    4.3
    Medium

    CVE-2006-5294

    Last Modified: 8 Oct 2013

    Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter.

    Source:Michiel Dethmers
    Published:16 Oct 2006
    7.5
    High

    CVE-2006-5292

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the toroot parameter.

    Source:Kacper
    Published:16 Oct 2006
    7.5
    High

    CVE-2006-5291

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition, so this issue is probably a duplicate of CVE-2006-4656.

    Source:v1per-haCker
    Published:16 Oct 2006
    7.5
    High

    CVE-2006-5289

    Last Modified: 4 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the calpath parameter to (1) modules/Calendar/admin/update.php, (2) modules/Calendar/admin/scheme.php, or (3) modules/Calendar/calendar.php.

    Source:the_day
    Published:13 Oct 2006
    5.1
    Medium

    CVE-2006-5284

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CFG[auth_phpbb_path] parameter.

    Source:Nima Salehi
    Published:13 Oct 2006
    7.5
    High

    CVE-2006-5283

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP code via a URL in the mostrar parameter.

    Source:Zickox
    Published:13 Oct 2006
    7.5
    High

    CVE-2006-5282

    Last Modified: 8 Dec 2016

    Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the scriptpath parameter to (1) report.php, (2) archive.php, (3) comments.php, (4) init.php, or (5) news.php.

    Source:v1per-haCker
    Published:13 Oct 2006
    7.5
    High

    CVE-2006-5281

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skin parameter.

    Source:mdx
    Published:13 Oct 2006
    10
    Critical

    CVE-2006-5276

    Last Modified: 30 Sept 2016

    Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire Intrusion Sensor; allows remote attackers to execute arbitrary code via crafted SMB traffic.

    Source:Winny Thomas
    Published:20 Feb 2007
    7.5
    High

    CVE-2006-5263

    Last Modified: 12 Sept 2016

    Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the language parameter, as demonstrated by a parameter value naming an Apache HTTP Server log file that apparently contains PHP code.

    Source:Nima Salehi
    Published:12 Oct 2006
    6.5
    Medium

    CVE-2006-5262

    Last Modified: 7 Oct 2013

    CRLF injection vulnerability in lib/session.php in Hastymail 1.5 and earlier before 20061008 allows remote authenticated users to send arbitrary IMAP commands via a CRLF sequence in a mailbox name. NOTE: the attack crosses privilege boundaries if the IMAP server configuration prevents a user from establishing a direct IMAP session.

    Source:Vicente Aguilera Diaz
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5261

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cfg_include_dir parameter in (1) disp_form.php3, (2) disp_smileys.php3, (3) little_news.php3, and (4) index.php3 in include/.

    Source:Mehmet Ince
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5259

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary PHP code via a URL in the folder parameter.

    Source:DarkFig
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5257

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.9.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_cache_path parameter.

    Source:Kacper
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5256

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.

    Source:k1tk4t
    Published:12 Oct 2006