10
    Critical

    CVE-2006-5156

    Last Modified: 23 Apr 2026

    Buffer overflow in McAfee ePolicy Orchestrator before 3.5.0.720 and ProtectionPilot before 1.1.1.126 allows remote attackers to execute arbitrary code via a request to /spipe/pkg/ with a long source header.

    Source:muts
    Published:3 Oct 2006
    7.5
    High

    CVE-2006-5155

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in core/pdf.php in VideoDB 2.2.1 and earlier allows remote attackers to execute arbitrary PHP code via the config[pdf_module] parameter.

    Source:Kacper
    Published:3 Oct 2006
    7.5
    High

    CVE-2006-5154

    Last Modified: 25 Nov 2016

    PHP remote file inclusion vulnerability in cp/sig.php in DeluxeBB 1.09 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the templatefolder parameter.

    Source:r0ut3r
    Published:3 Oct 2006
    7.5
    High

    CVE-2006-5148

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Forum82 2.5.2b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the repertorylevel parameter including scripts in /forum/ including (1) search.php, (2) message.php, (3) member.php, (4) mail.php, (5) lostpassword.php, (6) gesfil.php, (7) forum82lib.php3, and other unspecified scripts.

    Source:Silahsiz Kuvvetler
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5147

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in wamp_dir/setup/yesno.phtml in VAMP Webmail 2.0beta1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the no_url parameter.

    Source:Drago84
    Published:2 Oct 2006
    6.8
    Medium

    CVE-2006-5146

    Last Modified: 5 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Yblog allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in (a) funk.php, or the (2) action parameter in (b) tem.php and (c) uss.php.

    Source:You_You
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5145

    Last Modified: 5 Oct 2013

    Multiple SQL injection vulnerabilities in OlateDownload 3.4.0 allow remote attackers to execute arbitrary SQL commands via the (1) page parameter in details.php or the (2) query parameter in search.php.

    Source:Hessam-x
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5143

    Last Modified: 26 Sept 2016

    Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve Backup for Windows r11; BrightStor Enterprise Backup 10.5; Server Protection Suite r2; and Business Protection Suite r2 allow remote attackers to execute arbitrary code via crafted data on TCP port 6071 to the Backup Agent RPC Server (DBASVR.exe) using the RPC routines with opcode (1) 0x01, (2) 0x02, or (3) 0x18; invalid stub data on TCP port 6503 to the RPC routines with opcode (4) 0x2b or (5) 0x2d in ASCORE.dll in the Message Engine RPC Server (msgeng.exe); (6) a long hostname on TCP port 41523 to ASBRDCST.DLL in the Discovery Service (casdscsvc.exe); or unspecified vectors related to the (7) Job Engine Service.

    Source:Winny Thomas
    Published:6 Oct 2006
    7.5
    High

    CVE-2006-5141

    Last Modified: 5 Oct 2013

    PHP remote file inclusion vulnerability in script.php in Kevin A. Gordon Open Geo Targeting (aka geotarget) allows remote attackers to execute arbitrary PHP code via a URL in the anp_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:RaVeR shi mozi
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5140

    Last Modified: 12 Sept 2016

    SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Trex
    Published:2 Oct 2006
    5.1
    Medium

    CVE-2006-5137

    Last Modified: 23 Apr 2026

    Multiple direct static code injection vulnerabilities in Groupee UBB.threads 6.5.1.1 allow remote attackers to (1) inject PHP code via a theme[] array parameter to admin/doedittheme.php, which is injected into includes/theme.inc.php; (2) inject PHP code via a config[] array parameter to admin/doeditconfig.php, and then execute the code via includes/config.inc.php; and inject a reference to PHP code via a URL in the config[path] parameter, and then execute the code via (3) dorateuser.php, (4) calendar.php, and unspecified other scripts.

    Source:HACKERS PAL
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5135

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via a URL in the (1) open_box, (2) middle_box, and (3) close_box parameters in (a) sources/myaccount.php; the (4) navigation_end parameter in (b) navigation/search.php and (c) navigation/donation.php; and the (6) navigation_start and (7) navigation_middle parameters in navigation/donation.php, (d) navigation/latestnews.php, and (e) navigation/links.php; different vectors than CVE-2006-5092.

    Source:v1per-haCker
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5126

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in John Himmelman (aka DaRk2k1) PowerPortal 1.3a allows remote attackers to execute arbitrary PHP code via a URL in the file_name[] parameter.

    Source:v1per-haCker
    Published:2 Oct 2006
    5
    Medium

    CVE-2006-5125

    Last Modified: 23 Apr 2026

    Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remote attackers to obtain sensitive information via a directory name in the target parameter, which triggers a directory listing through the opendir function.

    Source:Mehmet Ince
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5124

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) target and (2) action parameters in window.php, and possibly the (3) target parameter in home.php.

    Source:Mehmet Ince
    Published:2 Oct 2006
    4
    Medium

    CVE-2006-5120

    Last Modified: 4 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Scott Metoyer Red Mombin 0.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors related to (1) index.php and (2) process_login.php.

    Source:Armorize Technologies
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5118

    Last Modified: 4 Oct 2013

    PHP remote file inclusion vulnerability in index.php3 in the PDD package for PHPSelect Web Development Division allows remote attackers to execute arbitrary PHP code via a URL in the Application_Root parameter.

    Source:rUnViRuS
    Published:2 Oct 2006
    5.1
    Medium

    CVE-2006-5115

    Last Modified: 12 Sept 2016

    Directory traversal vulnerability in kgcall.php in KGB 1.87 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the engine parameter, as demonstrated by uploading a file containing PHP code with an image/jpeg content type, and then referencing this file through the engine parameter.

    Source:Kacper
    Published:2 Oct 2006
    6.8
    Medium

    CVE-2006-5114

    Last Modified: 4 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in wgate in SAP Internet Transaction Server (ITS) 6.1 and 6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) ~urlmime or (2) ~command parameter, different vectors than CVE-2003-0749.

    Source:ILION Research
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5112

    Last Modified: 27 Oct 2016

    Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.

    Source:Metasploit
    Published:2 Oct 2006
    6.8
    Medium

    CVE-2006-5108

    Last Modified: 4 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to inject arbitrary web script or HTML via the order_id parameter in (1) admin/print_order.php and (2) view_order.php; the (3) site_url and (4) la_search_home parameters and (5) certain language parameters in admin/nav.php; the (6) image parameter in admin/image.php; the (7) site_name, (8) la_adm_header, (9) charset, and (10) certain other parameters in admin/header.inc.php; the (12) la_pow_by parameter in footer.inc.php; and the (13) site_name parameter and (14) certain other parameters in header.inc.php.

    Source:HACKERS PAL
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5107

    Last Modified: 9 Sept 2016

    Multiple SQL injection vulnerabilities in Devellion CubeCart 2.0.x allow remote attackers to execute arbitrary SQL commands via (1) the user_name parameter in admin/forgot_pass.php, (2) the order_id parameter in view_order.php, (3) the view_doc parameter in view_doc.php, and (4) the order_id parameter in admin/print_order.php.

    Source:HACKERS PAL
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5104

    Last Modified: 3 Oct 2013

    SQL injection vulnerability in global.php in Jelsoft vBulletin 2.x allows remote attackers to execute arbitrary SQL commands via the templatesused parameter.

    Source:HACKERS PAL
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5103

    Last Modified: 1 Oct 2013

    PHP remote file inclusion vulnerability in admin/index2.php in bbsNew 2.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the "right" parameter.

    Source:Root3r_H3ll
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5102

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NWCONF_SYSTEM[server_path] parameter.

    Source:Silahsiz Kuvvetler
    Published:2 Oct 2006
    7.5
    High

    CVE-2006-5100

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WN_BASEDIR parameter.

    Source:ThE-WoLf-KsA
    Published:2 Oct 2006
    6.8
    Medium

    CVE-2006-5096

    Last Modified: 4 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in VirtueMart (formerly known as mambo-phpShop) Joomla! eCommerce Edition CMS 1.0.11, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the Itemid parameter in a (1) com_contact or (2) subscribe action.

    Source:Adrian Castro
    Published:29 Sept 2006
    5.1
    Medium

    CVE-2006-5094

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_kb.php in the phpBB XS 2 (Spain version) allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter, a different vector than CVE-2006-4780 or CVE-2006-4893.

    Source:Mehmet Ince
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5093

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Tagmin Control Center in TagIt! Tagboard 2.1.B Build 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Kernel-32
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5092

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in navigation/menu.php in A-Blog 2 allows remote attackers to execute arbitrary PHP code via a URL in the navigation_start parameter.

    Source:Drago84
    Published:29 Sept 2006
    6.8
    Medium

    CVE-2006-5090

    Last Modified: 2 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Phoenix Evolution CMS (PECMS) allow remote attackers to inject arbitrary web script or HTML via the (1) mod or (2) action parameters in index.php, or the (3) pageid parameter in modules/pageedit/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Root3r_H3ll
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5089

    Last Modified: 2 Oct 2013

    PHP remote file inclusion vulnerability in mybic_server.php in Jim Plush My-BIC 0.6.5 allows remote attackers to execute arbitrary PHP code via a URL in the file parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. CVE disputes this vulnerability because the file variable is defined before use in a way that prevents arbitrary inclusion

    Source:Root3r_H3ll
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5087

    Last Modified: 12 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in evoBB 0.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the path parameter in (1) track.php or (2) connect.php.

    Source:SHiKaA
    Published:29 Sept 2006
    6.4
    Medium

    CVE-2006-5086

    Last Modified: 12 Sept 2016

    Blog Pixel Motion 2.1.1 allows remote attackers to change the username and password for the admin user via a direct request to insere_base.php with modified (1) login and (2) pass parameters. NOTE: this issue was claimed to be SQL injection by the original researcher, but it is not.

    Source:DarkFig
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5085

    Last Modified: 12 Sept 2016

    Static code injection vulnerability in config.php in Blog Pixel Motion 2.1.1 allows remote attackers to execute arbitrary PHP code via the nom_blog parameter, which is injected into include/variables.php.

    Source:DarkFig
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5084

    Last Modified: 4 Oct 2013

    Format string vulnerability in the NSRunAlertPanel function in eBay Skype for Mac 1.5.*.79 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a malformed Skype URL, as originally reported to involve a null dereference.

    Source:Tom Ferris
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5079

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path_to_bt_dir parameter.

    Source:Kacper
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5078

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _SESSION[dirMain] parameter.

    Source:Drago84
    Published:29 Sept 2006
    5.1
    Medium

    CVE-2006-5077

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Chris Smith Minerva Build 238 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:SHiKaA
    Published:29 Sept 2006
    7.5
    High

    CVE-2006-5076

    Last Modified: 1 Oct 2013

    Multiple PHP remote file inclusion vulnerabilities in OpenConcept Back-End 0.4.5 allow remote attackers to execute arbitrary PHP code via a URL in the includes_path parameter in (1) admin/index.php, (2) Facts.php, or (3) search.php.

    Source:Root3r_H3ll
    Published:29 Sept 2006
    5.1
    Medium

    CVE-2006-5074

    Last Modified: 4 Oct 2013

    Cross-site scripting (XSS) vulnerability in home.php in PHP Invoice 2.2 allows remote attackers to inject arbitrary web script or HTML via the alert parameter.

    Source:meto5757
    Published:29 Sept 2006
    5.1
    Medium

    CVE-2006-5070

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fsinit][objpath] parameter.

    Source:SHiKaA
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5068

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the o parameter.

    Source:SHiKaA
    Published:28 Sept 2006
    5.1
    Medium

    CVE-2006-5066

    Last Modified: 1 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DanPHPSupport 0.5, and other versions before 1.0, allow remote attackers to inject arbitrary web script or HTML via the (1) page parameter in index.php or the (2) do parameter in admin.php.

    Source:You_You
    Published:28 Sept 2006
    5.1
    Medium

    CVE-2006-5065

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[lib][db][path] parameter.

    Source:Drago84
    Published:28 Sept 2006
    5.1
    Medium

    CVE-2006-5064

    Last Modified: 1 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in BirdBlog 1.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) entryid parameter in comment.php, (2) page parameter in index.php, or the (3) uid parameter in user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Root3r_H3ll
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5062

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows remote attackers to execute arbitrary PHP code via a URL in the temppath parameter.

    Source:SHiKaA
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5061

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in mcf.php in Advanced-Clan-Script (AVCX) 3.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content parameter.

    Source:xdh
    Published:28 Sept 2006
    5.1
    Medium

    CVE-2006-5060

    Last Modified: 1 Oct 2013

    Cross-site scripting (XSS) vulnerability in login.php in Jamroom 3.0.16 and possibly earlier allows remote attackers to inject arbitrary web script or HTML via the forgot parameter in the forgot mode.

    Source:meto5757
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5058

    Last Modified: 11 Oct 2013

    Buffer overflow in (1) Call of Duty 1.5b and earlier, (2) Call of Duty United Offensive 1.51b and earlier, and (3) Call of Duty 2 1.3 and earlier allows remote attackers to execute arbitrary code via a long map argument to the "callvote map" command.

    Source:Luigi Auriemma
    Published:28 Sept 2006