7.5
    High

    CVE-2006-5254

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (com_registration_detailed), aka regdetailed, 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:k1tk4t
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5251

    Last Modified: 7 Oct 2013

    PHP remote file inclusion vulnerability in index.php in Deep CMS 2.0a allows remote attackers to execute arbitrary PHP code via a URL in the ConfigDir parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Crackers_Child
    Published:12 Oct 2006
    5.1
    Medium

    CVE-2006-5250

    Last Modified: 7 Oct 2013

    PHP remote file inclusion vulnerability in lib/googlesearch/GoogleSearch.php in BlueShoes 4.6_public and earlier allows remote attackers to execute arbitrary PHP code via a URL in the APP[path][lib] parameter, a different vector than CVE-2006-2864.

    Source:k1tk4t
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5249

    Last Modified: 7 Oct 2013

    PHP remote file inclusion vulnerability in tagmin/delTagUser.php in TagIt! Tagboard 2.1.B Build 2 (tagit2b) allows remote attackers to execute arbitrary PHP code via a URL in the configpath parameter.

    Source:k1tk4t
    Published:12 Oct 2006
    5.1
    Medium

    CVE-2006-5244

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Blog 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_read_file.php, and (5) lib_form_file.php in sw/lib_up_file; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified vectors.

    Source:the_day
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5243

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Doc 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) down_stat.php, (2) file.php, (3) find_file.php, (4) lib_file.php, and (5) lib_form_file.php in sw/lib_up_file/; (6) find_comment.php, (7) comment.php, and (8) lib_comment.php in sw/lib_comment/; (9) sw/lib_find/find.php; and other unspecified PHP scripts.

    Source:the_day
    Published:12 Oct 2006
    5.1
    Medium

    CVE-2006-5241

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in OpenDock Easy Gallery 1.4 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the doc_directory parameter in (1) file.php; (2) find_user.php, (3) lib_user.php, (4) lib_form_user.php, and (5) user.php in sw/lib_user/; (6) find_session.php and (7) session.php in sw/lib_session/; (8) comment.php and (9) lib_comment.php in sw/lib_comment/; and other unspecified PHP scripts.

    Source:the_day
    Published:12 Oct 2006
    5.1
    Medium

    CVE-2006-5240

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the MY_ENV[BASE_ENGINE_LOC] parameter.

    Source:K-159
    Published:12 Oct 2006
    4.3
    Medium

    CVE-2006-5239

    Last Modified: 7 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the captcha_session_code parameter in pre_details.php.

    Source:Tamriel
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-5236

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL commands via the search_user parameter.

    Source:Master Mind
    Published:11 Oct 2006
    7.5
    High

    CVE-2006-5234

    Last Modified: 22 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in phpWebSite 0.10.2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPWS_SOURCE_DIR parameter in (1) init.php, (2) users.php, (3) Cookie.php, (4) forms.php, (5) Groups.php, (6) ModSetting.php, (7) Calendar.php, (8) DateTime.php, (9) core.php, (10) ImgLibrary.php, (11) Manager.php, and (12) Template.php, and (13) EZform.php. NOTE: CVE disputes this report, since "PHPWS_SOURCE_DIR" is defined as a constant, not accessed as a variable

    Source:Crackers_Child
    Published:11 Oct 2006
    7.5
    High

    CVE-2006-5232

    Last Modified: 7 Oct 2013

    Multiple PHP remote file inclusion vulnerabilities in iSearch 2.16 allow remote attackers to execute arbitrary PHP code via a URL in the isearch_path parameter in (1) index.php, (2) viewcache.php, (3) sitemap.php, (4) isearch.inc.php, (5) google_sitemap.php, (6) stats.php, or (7) auto_spider_img.php. NOTE: this issue has been disputed by a third party who shows that $isearch_path is set to a constant value. CVE analysis as of 20061010 is inconclusive, although the original researcher is known to make mistakes

    Source:MoHaNdKo
    Published:11 Oct 2006
    7.5
    High

    CVE-2006-5230

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

    Source:Mehmet Ince
    Published:11 Oct 2006
    2.6
    Low

    CVE-2006-5229

    Last Modified: 27 Sept 2016

    OpenSSH portable 4.1 on SUSE Linux, and possibly other platforms and versions, and possibly under limited configurations, allows remote attackers to determine valid usernames via timing discrepancies in which responses take longer for valid usernames than invalid ones, as demonstrated by sshtime. NOTE: as of 20061014, it appears that this issue is dependent on the use of manually-set passwords that causes delays when processing /etc/shadow due to an increased number of rounds.

    Source:Marco Ivaldi
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5228

    Last Modified: 7 Oct 2013

    Multiple SQL injection vulnerabilities in the Google Gadget login.php (gadget/login.php) in Rob Hensley ackerTodo 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) up_login, (2) up_pass, or (3) up_num_tasks parameters.

    Source:Francesco Laurita
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5226

    Last Modified: 8 Dec 2016

    PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Source:Mehmet Ince
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5224

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/logger_engine.php in Dimitri Seitz Security Suite IP Logger 1.0.0 in dwingmods for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:SpiderZ
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5223

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tracker module 1.0 and earlier for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5222

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter in (1) includes/themen_portal_mitte.php or (2) includes/logger_engine.php.

    Source:SpiderZ
    Published:10 Oct 2006
    7.5
    High

    CVE-2006-5221

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) matiere_ID parameter in lire.php or the (2) classe_ID parameter in lire_a_faire.php.

    Source:s4mi
    Published:10 Oct 2006
    5.1
    Medium

    CVE-2006-5220

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the webyep_sIncludePath in (1) files in the programm/lib/ directory including (a) WYApplication.php, (b) WYDocument.php, (c) WYEditor.php, (d) WYElement.php, (e) WYFile.php, (f) WYHTMLTag.php, (g) WYImage.php, (h) WYLanguage.php, (i) WYLink.php, (j) WYPath.php, (k) WYPopupWindowLink.php, (l) WYSelectMenu.php, and (m) WYTextArea.php; (2) files in the programm/elements/ directory including (n) WYGalleryElement.php, (o) WYGuestbookElement.php, (p) WYImageElement.php, (q) WYLogonButtonElement.php, (r) WYLongTextElement.php, (s) WYLoopElement.php, (t) WYMenuElement.php, and (u) WYShortTextElement.php; and (3) programm/webyep.php.

    Source:the_day
    Published:9 Oct 2006
    5.1
    Medium

    CVE-2006-5219

    Last Modified: 7 Oct 2013

    SQL injection vulnerability in blog/index.php in the blog module in Moodle 1.6.2 allows remote attackers to execute arbitrary SQL commands via a double-encoded tag parameter.

    Source:disfigure
    Published:9 Oct 2006
    7.5
    High

    CVE-2006-5217

    Last Modified: 7 Oct 2013

    SQL injection vulnerability in giris_yap.asp in Emek Portal 2.1 allows remote attackers to execute arbitrary SQL commands by simultaneously injecting into the user name and pass fields in uyegiris.asp, also known as the Kullanici Adi (k_a) and Sifre (sifre) parameters.

    Source:Dj ReMix
    Published:9 Oct 2006
    7.5
    High

    CVE-2006-5216

    Last Modified: 5 Oct 2017

    Stack-based buffer overflow in Sergey Lyubka Simple HTTPD (shttpd) 1.34 allows remote attackers to execute arbitrary code via a long URI.

    Source:SkOd
    Published:9 Oct 2006
    5
    Medium

    CVE-2006-5210

    Last Modified: 7 Oct 2013

    Directory traversal vulnerability in IronWebMail before 6.1.1 HotFix-17 allows remote attackers to read arbitrary files via a GET request to the IM_FILE identifier with double-url-encoded "../" sequences ("%252e%252e/").

    Source:Derek Callaway
    Published:16 Oct 2006
    7.5
    High

    CVE-2006-5209

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 and earlier, as used in phpBB 2.0 up to 2.0.21, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:SpiderZ
    Published:9 Oct 2006
    7.5
    High

    CVE-2006-5208

    Last Modified: 23 Apr 2026

    Multiple SQL injection vulnerabilities in PHP Classifieds 7.1 allow remote attackers to execute arbitrary SQL commands via (1) the catid_search parameter in search.php and (2) the catid parameter in index.php.

    Source:Kzar
    Published:9 Oct 2006
    5.1
    Medium

    CVE-2006-5207

    Last Modified: 5 Oct 2017

    PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the smileys_dir parameter.

    Source:Mehmet Ince
    Published:9 Oct 2006
    7.5
    High

    CVE-2006-5206

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the album parameter in (1) index.php and (2) forum/index.php, when the rate command in the gallery automodule is used.

    Source:1nf3ct0r
    Published:9 Oct 2006
    5
    Medium

    CVE-2006-5205

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the dir parameter in (1) index.php and (2) forum/index.php, when the viewimage command in the gallery module is used.

    Source:1nf3ct0r
    Published:9 Oct 2006
    5
    Medium

    CVE-2006-5202

    Last Modified: 24 Jan 2017

    Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attackers to modify arbitrary configurations via a direct request to Security.tri, as demonstrated using the SecurityMode and layout parameters, a different issue than CVE-2006-2559.

    Source:meathive
    Published:9 Oct 2006
    4
    Medium

    CVE-2006-5198

    Last Modified: 10 Mar 2011

    The WZFILEVIEW.FileViewCtrl.61 ActiveX control (aka Sky Software "FileView" ActiveX control) for WinZip 10.0 before build 7245 allows remote attackers to execute arbitrary code via unspecified "unsafe methods."

    Source:Metasploit
    Published:14 Nov 2006
    7.8
    High

    CVE-2006-5196

    Last Modified: 5 Oct 2013

    The HTTP interface in the Motorola SURFboard SB4200 Cable Modem allows remote attackers to cause a denial of service (device crash) via a request with MfcISAPICommand set to SecretProc and a long string in the Secret parameter.

    Source:Dave Gil
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5193

    Last Modified: 6 Oct 2013

    PHP remote file inclusion vulnerability in index.php in Josh Schmidt WikyBlog 1.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the includeDir parameter.

    Source:MoHaNdKo
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5192

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in includes/footer.php in phpGreetz 0.99 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHPGREETZ_INCLUDE_DIR parameter.

    Source:mozi
    Published:6 Oct 2006
    5.1
    Medium

    CVE-2006-5191

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for phpBB 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Kw3[R]Ln
    Published:6 Oct 2006
    4.3
    Medium

    CVE-2006-5190

    Last Modified: 4 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in the (a) banner_manager.php, (b) banner_statistics.php, (c) countries.php, (d) currencies.php, (e) languages.php, (f) manufacturers.php, (g) newsletters.php, (h) orders_status.php, (i) products_attributes.php, (j) products_expected.php, (k) reviews.php, (l) specials.php, (m) stats_products_purchased.php, (n) stats_products_viewed.php, (o) tax_classes.php, (p) tax_rates.php, or (q) zones.php scripts in /admin, and the (2) zpage parameter in (r) admin/geo_zones.php.

    Source:Lostmon
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5189

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appl[APPL] parameter.

    Source:Kacper
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5187

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in Bulletin Board Ace (BBaCE) 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:SpiderZ
    Published:6 Oct 2006
    5.1
    Medium

    CVE-2006-5186

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.

    Source:mozi
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5182

    Last Modified: 1 Dec 2016

    PHP remote file inclusion vulnerability in frontpage.php in Dan Jensen Travelsized CMS 0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the setup_folder parameter.

    Source:Kacper
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5181

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the target parameter in (1) change_preferences2.php, (2) create_file.php, (3) upload_local.php, and (4) upload_multi.php, different vectors than CVE-2006-5124.

    Source:Mehmet Ince
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5180

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter, a different vector than CVE-2006-5102.

    Source:Mehmet Ince
    Published:6 Oct 2006
    6.2
    Medium

    CVE-2006-5178

    Last Modified: 23 Apr 2026

    Race condition in the symlink function in PHP 5.1.6 and earlier allows local users to bypass the open_basedir restriction by using a combination of symlink, mkdir, and unlink functions to change the file path after the open_basedir check and before the file is opened by the underlying system, as demonstrated by symlinking a symlink into a subdirectory, to point to a parent directory via .. (dot dot) sequences, and then unlinking the resulting symlink.

    Source:Maksymilian Arciemowicz
    Published:6 Oct 2006
    9.3
    Critical

    CVE-2006-5177

    Last Modified: 5 Oct 2013

    The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer over-read.

    Source:mu-b
    Published:6 Oct 2006
    5.1
    Medium

    CVE-2006-5167

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) BSX_LIBDIR parameter in scripts in /files/ including (a) abook.php3, (b) compose-attach.php3, (c) compose-menu.php3, (d) compose-new.php3, (e) compose-send.php3, (f) folder-create.php3, (g) folder-delete.php3, (h) folder-empty.php3, (i) folder-rename.php3, (j) folders.php3, (k) mbox-action.php3, (l) mbox-list.php3, (m) message-delete.php3, (n) message-forward.php3, (o) message-header.php3, (p) message-print.php3, (q) message-read.php3, (r) message-reply.php3, (s) message-replyall.php3, (t) message-search.php3, or (u) settings.php3; and the (2) BSX_HTXDIR parameter in (v) files/login.php3.

    Source:Kacper
    Published:4 Oct 2006
    7.5
    High

    CVE-2006-5166

    Last Modified: 5 Oct 2013

    PHP remote file inclusion vulnerability in functions.php in PHP Web Scripts Easy Banner Free allows remote attackers to execute arbitrary PHP code via a URL in the s[phppath] parameter.

    Source:abu ahmed
    Published:4 Oct 2006
    5.1
    Medium

    CVE-2006-5165

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[ppa_root_path] parameter.

    Source:Kacper
    Published:4 Oct 2006
    6.8
    Medium

    CVE-2006-5164

    Last Modified: 5 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cart.php in Sum Effect Software digiSHOP 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) sortBy or (2) search parameters.

    Source:meto5757
    Published:4 Oct 2006
    5
    Medium

    CVE-2006-5162

    Last Modified: 31 Aug 2016

    wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unhandled exception and crash) via a long Content-Type header, which triggers a stack overflow.

    Source:Firestorm
    Published:3 Oct 2006