5.1
    Medium

    CVE-2006-5057

    Last Modified: 1 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Ktools.net PhotoStore allow remote attackers to inject arbitrary web script or HTML via the (1) gid parameter in details.php, or the (2) photogid parameter in view_photog.php.

    Source:meto5757
    Published:28 Sept 2006
    5.1
    Medium

    CVE-2006-5056

    Last Modified: 1 Oct 2013

    Cross-site scripting (XSS) vulnerability in index.php in Opial Audio/Video Download Management 1.0 allows remote attackers to inject arbitrary web script or HTML via the destination parameter in the Login view.

    Source:meto5757
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5055

    Last Modified: 12 Sept 2016

    PHP remote file inclusion vulnerability in admin/testing/tests/0004_init_urls.php in syntaxCMS 1.1.1 through 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the init_path parameter.

    Source:MoHaJaLi
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5054

    Last Modified: 6 Jan 2017

    SQL injection vulnerability in uye/uye_ayrinti.asp in iyzi Forum 1 Beta 2 and earlier allows remote attackers to execute arbitrary SQL commands via the uye_nu parameter.

    Source:Fix TR
    Published:28 Sept 2006
    7.5
    High

    CVE-2006-5053

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the content_page parameter.

    Source:Drago84
    Published:28 Sept 2006
    8.1
    High

    CVE-2006-5051

    Last Modified: 23 Apr 2026

    Signal handler race condition in OpenSSH before 4.4 allows remote attackers to cause a denial of service (crash), and possibly execute arbitrary code if GSSAPI authentication is enabled, via unspecified vectors that lead to a double-free.

    Published:27 Sept 2006
    6.8
    Medium

    CVE-2006-5048

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier for Joomla! allow remote attackers to execute arbitrary code via a URL in the mosConfig_absolute_path parameter in (1) configinsert.php, (2) lang.php, (3) client.php, and (4) server.php.

    Source:Drago84
    Published:27 Sept 2006
    6.8
    Medium

    CVE-2006-5045

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in PollXT component (com_pollxt) 1.22.07 and earlier for Joomla! has unspecified impact and attack vectors, probably related to PHP remote file inclusion in the mosConfig_absolute_path to conf.pollxt.php.

    Source:vitux
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5044

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in Prince Clan (Princeclan) Chess component (com_pcchess) 0.8 and earlier for Mambo and Joomla! has unspecified impact and attack vectors.

    Source:OLiBekaS
    Published:27 Sept 2006
    6.8
    Medium

    CVE-2006-5043

    Last Modified: 29 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) file_upload.php or (2) image_upload.php, a variant of CVE-2006-3528.

    Source:Cold Zero
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5034

    Last Modified: 25 Sept 2013

    Directory traversal vulnerability in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the URI.

    Source:securma massine
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5033

    Last Modified: 25 Sept 2013

    Unspecified vulnerability in StoresAndCalendarsList.cgi in Paul Smith Computer Services vCAP 1.9.0 Beta and earlier allows remote attackers to cause a denial of service via the session parameter, possibly related to format string specifiers or malformed URL encoding.

    Source:securma massine
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5032

    Last Modified: 23 Apr 2026

    PHP remote file inclusion vulnerability in dix.php3 in PHPartenaire 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the url_phpartenaire parameter.

    Source:DaDIsS
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5031

    Last Modified: 5 Jan 2018

    Directory traversal vulnerability in app/webroot/js/vendors.php in Cake Software Foundation CakePHP before 1.1.8.3544 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter, followed by a filename ending with "%00" and a .js filename.

    Source:GulfTech Security
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5030

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users to execute arbitrary SQL commands via the sort parameter.

    Source:rgod
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5028

    Last Modified: 30 Sept 2013

    Directory traversal vulnerability in filemanager/filemanager.php in SWsoft Plesk 7.5 Reload and Plesk 7.6 for Microsoft Windows allows remote attackers to list arbitrary directories via a ../ (dot dot slash) in the file parameter in a chdir action.

    Source:GuanYu
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5023

    Last Modified: 23 Apr 2026

    SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the kategori parameter.

    Source:Muhacir
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5022

    Last Modified: 5 Dec 2016

    PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allows remote attackers to execute arbitrary PHP code via a URL in the nbs parameter.

    Source:CvIr.System
    Published:27 Sept 2006
    9.8
    Critical

    CVE-2006-5021

    Last Modified: 29 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in redgun RedBLoG 0.5 allow remote attackers to execute arbitrary PHP code via a URL in (1) the root parameter in imgen.php, and the root_path parameter in (2) admin/config.php, (3) common.php, and (4) admin/index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Root3r_H3ll
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5020

    Last Modified: 23 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SolidState 0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the base_path parameter in manager/pages/ scripts including (1) AccountsPage.class.php, (2) AddInvoicePage.class.php, (3) AddIPAddressPage.class.php, (4) AddPaymentPage.class.php, (5) AddTaxRulePage.class.php, (6) AssignDomainPage.class.php, (7) AssignHostingPage.class.php, (8) AssignProductPage.class.php, (9) BillingPage.class.php, (10) BillingPaymentPage.class.php, (11) BrowseAccountsPage.class.php, (12) BrowseInvoicesPage.class.php, (13) ConfigureEditUserPage.class.php, (14) ConfigureNewUserPage.class.php, (15) ConfigureNewUserReceiptPage.class.php, (16) ConfigureUsersPage.class.php, (17) DeleteAccountPage.class.php, (18) DeleteDomainServicePage.class.php, (19) DeleteHostingServicePage.class.php, (20) DeleteInvoicePage.class.php, (21) DeleteProductPage.class.php, (22) DeleteServerPage.class.php, (23) DomainServicesPage.class.php, (24) DomainsPage.class.php, (25) EditAccountPage.class.php, (26) EditDomainPage.class.php, (27) EditDomainServicePage.class.php, (28) EditHostingServicePage.class.php, (29) EditPaymentPage.class.php, (30) EditProductPage.class.php, (31) EditServerPage.class.php, (32) EmailInvoicePage.class.php, (33) ExecuteOrderPage.class.php, (34) ExpiredDomainsPage.class.php, (35) FulfilledOrdersPage.class.php, (36) GenerateInvoicesPage.class.php, (37) HomePage.class.php, (38) InactiveAccountsPage.class.php, (39) IPManagerPage.class.php, (40) LoginPage.class.php, (41) LogPage.class.php, (42) ModulesPage.class.php, (43) NewAccountPage.class.php, (44) NewDomainServicePage.class.php, (45) NewProductPage.class.php, (46) OutstandingInvoicesPage.class.php, (47) PendingAccountsPage.class.php, (48) PendingOrdersPage.class.php, (49) PrintInvoicePage.class.php, (50) ProductsPage.class.php, (51) RegisterDomainPage.class.php, (52) RegisteredDomainsPage.class.php, (53) ServersPage.class.php, (54) ServicesHostingServicesPage.class.php, (55) ServicesNewHostingPage.class.php, (56) ServicesPage.class.php, (57) ServicesWebHostingPage.class.php, (58) SettingsPage.class.php, (59) TaxesPage.class.php, (60) TransferDomainPage.class.php, (61) ViewAccountPage.class.php, (62) ViewDomainServicePage.class.php, (63) ViewHostingServicePage.class.php, (64) ViewInvoicePage.class.php, (65) ViewLogMessagePage.class.php, (66) ViewOrderPage.class.php, (67) ViewProductPage.class.php, (68) ViewServerPage.class.php, (69) WelcomeEmailPage.class.php; and (70) modules/RegistrarModule.class.php, (71) modules/SolidStateModule.class.php, (72) modules/authorizeaim/authorizeaim.class.php, and (73) modules/authorizeaim/pages/AAIMConfigPage.class.php.

    Source:Kacper
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5019

    Last Modified: 30 Sept 2013

    Google Mini 4.4.102.M.36 and earlier allows remote attackers to obtain sensitive information via a direct request for /search with an invalid client parameter, which reveals the path in an error message.

    Source:Patrick Webster
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-5017

    Last Modified: 15 Dec 2016

    SQL injection vulnerability in admin/all_users.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to execute arbitrary SQL commands via the from parameter.

    Source:HACKERS PAL
    Published:27 Sept 2006
    5
    Medium

    CVE-2006-5016

    Last Modified: 21 Dec 2016

    Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, allows remote attackers to upload arbitrary files to the /imagebank directory.

    Source:Khashayar Fereidani
    Published:27 Sept 2006
    8.8
    High

    CVE-2006-5014

    Last Modified: 23 Apr 2026

    Unspecified vulnerability in cPanel before 10.9.0 12 Tree allows remote authenticated users to gain privileges via unspecified vectors in (1) mysqladmin and (2) hooksadmin.

    Source:Clint Torrez
    Published:27 Sept 2006
    7.5
    High

    CVE-2006-4993

    Last Modified: 22 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _AMGconfig[cfg_serverpath] parameter in (1) modules/AllMyGuests/signin.php (aka the Nuke module) and (2) AllMyGuests/signin.php (aka the standalone).

    Source:Br@Him
    Published:26 Sept 2006
    7.5
    High

    CVE-2006-4992

    Last Modified: 4 May 2017

    Multiple PHP remote file inclusion vulnerabilities in JD-WordPress for Joomla! (com_jd-wp) 2.0-1.0 RC2 allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) wp-comments-post.php, (2) wp-feed.php, or (3) wp-trackback.php.

    Source:Drago84
    Published:26 Sept 2006
    5
    Medium

    CVE-2006-4989

    Last Modified: 7 Oct 2017

    Patrick Michaelis Wili-CMS allows remote attackers to obtain sensitive information via a direct request for (1) thumbnail.php, (2) functions/admin/all.php, (3) functions/admin/init_session.php, (4) functions/all.php, and (5) certain files in example-view/admin_templates/, which reveals the path in various error messages.

    Source:HACKERS PAL
    Published:26 Sept 2006
    4.3
    Medium

    CVE-2006-4988

    Last Modified: 7 Oct 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to inject arbitrary web script or HTML via (1) the query string to relocate.php, (2) the globals[pageid] parameter in example-view/inc/print_button.php, and other unspecified vectors.

    Source:HACKERS PAL
    Published:26 Sept 2006
    7.5
    High

    CVE-2006-4987

    Last Modified: 7 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in Patrick Michaelis Wili-CMS allow remote attackers to execute arbitrary PHP code via a URL in the globals[content_dir] parameter in (1) example-view/templates/article.php, (2) example-view/templates/root.php, and (3) example-view/templates/dates_list.php.

    Source:HACKERS PAL
    Published:26 Sept 2006
    4.3
    Medium

    CVE-2006-4985

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Grayscale BandSite CMS allow remote attackers to inject arbitrary web script or HTML via (1) the max_file_size_purdy parameter in adminpanel/includes/helpfiles/help_mp3.php, (2) the message_text parameter in adminpanel/includes/mailinglist/sendemail.php, (3) the this_year parameter in includes/footer.php, and the band parameter in (4) adminpanel/includes/helpfiles/help_news.php (5) adminpanel/includes/helpfiles/help_merch.php, (6) adminpanel/includes/header.php, and (7) adminpanel/login_header.php; and includes/content/ files including (8) bio_content.php, (9) gbook_content.php, (10) interview_content.php, (11) links_content.php, (12) lyrics_content.php, (13) member_content.php, (14) merch_content.php, (15) mp3_content.php, (16) news_content.php, (17) pastshows_content.php, (18) photo_content.php, (19) releases_content.php, (20) reviews_content.php, (21) shows_content.php, and (22) signgbook_content.php.

    Source:HACKERS PAL
    Published:26 Sept 2006
    5
    Medium

    CVE-2006-4979

    Last Modified: 9 Sept 2016

    Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows remote attackers to inject arbitrary PHP code in config.inc.php via modified configuration settings.

    Source:simo64
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4978

    Last Modified: 9 Sept 2016

    Multiple SQL injection vulnerabilities in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the univers parameter in score.php and (2) the quiz_id parameter in home.php, accessed through the front/ URI.

    Source:simo64
    Published:25 Sept 2006
    5
    Medium

    CVE-2006-4977

    Last Modified: 9 Sept 2016

    Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Beschmout PhpQuiz 1.2 and earlier allow remote attackers to upload arbitrary PHP code to the phpquiz/img_quiz folder via the (a) upload, (b) ok_update, (c) image, and (d) path parameters, possibly requiring directory traversal sequences in the path parameter.

    Source:simo64
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4974

    Last Modified: 16 Apr 2026

    Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a long response to a PASV command.

    Source:h07
    Published:25 Sept 2006
    4.3
    Medium

    CVE-2006-4973

    Last Modified: 29 Sept 2013

    Cross-site scripting (XSS) vulnerability in Default.aspx in Perpetual Motion Interactive Systems DotNetNuke before 3.3.5, and 4.x before 4.3.5, allows remote attackers to inject arbitrary HTML via the error parameter.

    Source:Secure Shapes
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4970

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to execute arbitrary PHP code via a URL in the Home_Path parameter.

    Source:Saudi Hackrz
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4969

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arbitrary PHP code via a URL in the Inc_Dir parameter in (1) affiliates.php, (2) orders.php, (3) events.php, (4) index.php, (5) articles.php, (6) faqs.php, (7) guestbook.php, (8) catalog.php, (9) wholesale.php, (10) weblinks.php, (11) certificates.php, (12) sitesearch.php, (13) contact.php, (14) sitemap.php, (15) search.php, (16) registry.php, or (17) error.php.

    Source:SnIpEr_SA
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4968

    Last Modified: 12 Jan 2017

    PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:AzzCoder
    Published:25 Sept 2006
    7.5
    High

    CVE-2006-4966

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in inc/ifunctions.php in chumpsoft phpQuestionnaire (phpQ) 3.12 allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[phpQRootDir] parameter.

    Source:Solpot
    Published:25 Sept 2006
    5
    Medium

    CVE-2006-4965

    Last Modified: 30 Sept 2013

    Apple QuickTime 7.1.3 Player and Plug-In allows remote attackers to execute arbitrary JavaScript code and possibly conduct other attacks via a QuickTime Media Link (QTL) file with an embed XML element and a qtnext parameter that identifies resources outside of the original domain. NOTE: as of 20070912, this issue has been demonstrated by using instances of Components.interfaces.nsILocalFile and Components.interfaces.nsIProcess to execute arbitrary local files within Firefox and possibly Internet Explorer.

    Source:LMH
    Published:25 Sept 2006
    6.4
    Medium

    CVE-2006-4963

    Last Modified: 9 Sept 2016

    Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence in the view parameter in the show_view action in the calendarmodule module, as demonstrated by executing PHP code through session files.

    Source:rgod
    Published:23 Sept 2006
    6.4
    Medium

    CVE-2006-4962

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pbd_engine.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence via the phpExt parameter, as demonstrated by executing PHP code in a log file.

    Source:Kacper
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4961

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dragon 2.9.1 and earlier allows remote attackers to execute arbitrary SQL commands via the m parameter to index.php.

    Source:Kacper
    Published:23 Sept 2006
    6.8
    Medium

    CVE-2006-4960

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter, which is reflected in an error message resulting from a failed SQL query.

    Source:Kacper
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4957

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to execute arbitrary SQL commands via the email parameter to Admin.php.

    Source:STILPU
    Published:23 Sept 2006
    6.8
    Medium

    CVE-2006-4956

    Last Modified: 29 Sept 2013

    Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote attackers to inject arbitrary web script or HTML via the in_name parameter, as used by the Name field.

    Source:Tan Chew Keong
    Published:23 Sept 2006
    5
    Medium

    CVE-2006-4955

    Last Modified: 20 Oct 2017

    Directory traversal vulnerability in the downloadfile servlet in Neon WebMail for Java before 5.08 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the (1) savefolder and (2) savefilename parameters.

    Source:Tan Chew Keong
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4954

    Last Modified: 20 Oct 2017

    The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote attackers to modify information of arbitrary users, as demonstrated by modifying (1) passwords and (2) permissions, (3) viewing profile settings, and (4) creating and (5) deleting users.

    Source:Tan Chew Keong
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4953

    Last Modified: 20 Oct 2017

    Multiple SQL injection vulnerabilities in Neon WebMail for Java before 5.08 allow remote attackers to execute arbitrary SQL commands via the (1) adr_sortkey and (2) adr_sortkey_desc parameters in the (a) addrlist servlet, and the (3) sortkey and (4) sortkey_desc parameters in the (b) maillist servlet.

    Source:Tan Chew Keong
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4952

    Last Modified: 20 Oct 2017

    The updatemail servlet in Neon WebMail for Java before 5.08 allows remote attackers to move e-mail messages of arbitrary users between different mail folders, specified by the folderid and tofolderid parameters, via the ID parameter.

    Source:Tan Chew Keong
    Published:23 Sept 2006