7.5
    High

    CVE-2006-4948

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to execute arbitrary code or cause a denial of service via a long file name. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Metasploit
    Published:23 Sept 2006
    5.1
    Medium

    CVE-2006-4946

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.99, and possibly 2.5 Beta and earlier, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:ajann
    Published:23 Sept 2006
    5.1
    Medium

    CVE-2006-4945

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _PHPLIB[libdir] parameter to (1) rechnung.php or (2) prepend.php.

    Source:ajann
    Published:23 Sept 2006
    7.5
    High

    CVE-2006-4944

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpdns_basedir parameter.

    Source:Kacper
    Published:23 Sept 2006
    4.6
    Medium

    CVE-2006-4927

    Last Modified: 6 Sept 2016

    The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec AntiVirus and security products, allow local users to gain privileges by overwriting critical system addresses using a crafted Irp to the IOCTL functions (1) 0x222AD3, (2) 0x222AD7, and (3) 0x222ADB.

    Source:Ruben Santamarta
    Published:5 Oct 2006
    7.2
    High

    CVE-2006-4926

    Last Modified: 22 Nov 2017

    The NDIS-TDI Hooking Engine, as used in the (1) KLICK (KLICK.SYS) and (2) KLIN (KLIN.SYS) device drivers 2.0.0.281 for in Kaspersky Labs Anti-Virus 6.0.0.303 and other Anti-Virus and Internet Security products, allows local users to execute arbitrary code via crafted Irp structure with invalid addresses in the 0x80052110 IOCTL.

    Source:Nanika
    Published:20 Oct 2006
    7.8
    High

    CVE-2006-4924

    Last Modified: 12 Sept 2016

    sshd in OpenSSH before 4.4, when using the version 1 SSH protocol, allows remote attackers to cause a denial of service (CPU consumption) via an SSH packet that contains duplicate blocks, which is not properly handled by the CRC compensation attack detector.

    Source:Tavis Ormandy
    Published:19 Sept 2006
    4.3
    Medium

    CVE-2006-4923

    Last Modified: 29 Sept 2013

    Cross-site scripting (XSS) vulnerability in search.php in eSyndiCat Portal System allows remote attackers to inject arbitrary web script or HTML via the what parameter.

    Source:meto5757
    Published:21 Sept 2006
    5
    Medium

    CVE-2006-4922

    Last Modified: 9 Sept 2016

    Unrestricted file upload vulnerability in starnet/editors/htmlarea/popups/images.php in Site@School (S@S) 2.4.02 and earlier allows remote attackers to upload and execute arbitrary files with executable extensions.

    Source:simo64
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4921

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in Site@School (S@S) 2.4.03 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to starnet/modules/include/include.php. NOTE: some of these details are obtained from third party information.

    Source:simo64
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4920

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the cmsdir parameter to (1) starnet/modules/sn_allbum/slideshow.php, and (2) starnet/themes/editable/main.inc.php.

    Source:simo64
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4918

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Simple Discussion Board 0.1.0 allow remote attackers to execute arbitrary PHP code via a URL in the (1) env_dir parameter to (a) blank.php, (b) admin.php, or (c) builddb.php, and the (2) script_root parameter to blank.php.

    Source:CeNGiZ-HaN
    Published:21 Sept 2006
    4.3
    Medium

    CVE-2006-4917

    Last Modified: 29 Sept 2013

    Cross-site scripting (XSS) vulnerability in search.php in PT News 1.7.8 allows remote attackers to inject arbitrary web script or HTML via the pgname parameter.

    Source:Snake
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4916

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in uye_profil.asp in Tekman Portal (TR) 1.0 allows remote attackers to execute arbitrary SQL commands via the uye_id parameter.

    Source:Fix TR
    Published:21 Sept 2006
    4.3
    Medium

    CVE-2006-4915

    Last Modified: 29 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in Innovate Portal 2.0 allows remote attackers to inject arbitrary web script or HTML via the content parameter.

    Source:meto5757
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4913

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to include arbitrary local files and possibly execute arbitrary code via a .. (dot dot) sequence and trailing null (%00) byte in the lang parameter, as demonstrated by injecting PHP code into a log file.

    Source:Kw3[R]Ln
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4912

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in PHP DocWriter 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script parameter.

    Source:Kacper
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4906

    Last Modified: 9 Sept 2016

    SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbitrary SQL commands via the new_calendarid parameter.

    Source:x128
    Published:21 Sept 2006
    7.5
    High

    CVE-2006-4904

    Last Modified: 19 Jan 2018

    Dynamic variable evaluation vulnerability in cmpi.php in Qualiteam X-Cart 4.1.3 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code, as demonstrated by PHP remote file inclusion via the xcart_dir parameter.

    Source:GulfTech Security
    Published:21 Sept 2006
    6.4
    Medium

    CVE-2006-4901

    Last Modified: 30 Sept 2013

    Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, and eTrust Audit 1.5 and r8, allows remote attackers to spoof alerts and conduct replay attacks by invoking eTSAPISend.exe with the desired arguments.

    Source:Patrick Webster
    Published:22 Sept 2006
    5.5
    Medium

    CVE-2006-4900

    Last Modified: 30 Sept 2013

    Directory traversal vulnerability in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, allows remote authenticated users to read and delete arbitrary files via ".." sequences in the eSCCAdHocHtmlFile parameter to eSMPAuditServlet, which is not properly handled by the getadhochtml function.

    Source:Patrick Webster
    Published:22 Sept 2006
    5
    Medium

    CVE-2006-4899

    Last Modified: 30 Sept 2013

    The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running on Windows, allows remote attackers to obtain the web server path via a "'" (single quote) in the PIProfile function, which leaks the path in an error message.

    Source:Patrick Webster
    Published:22 Sept 2006
    7.5
    High

    CVE-2006-4898

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the appconf[rootpath] parameter.

    Source:SHiKaA
    Published:19 Sept 2006
    5
    Medium

    CVE-2006-4897

    Last Modified: 16 Apr 2026

    CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, which allows remote attackers to obtain the administrator password.

    Source:Kacper
    Published:19 Sept 2006
    4.3
    Medium

    CVE-2006-4894

    Last Modified: 28 Sept 2013

    Cross-site scripting (XSS) vulnerability in forms/lostpassword.php in iDevSpot NixieAffiliate 1.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the error parameter.

    Source:s3rv3r_hack3r
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4892

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:ajann
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4891

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the key parameter.

    Source:ajann
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4890

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dirroot parameter to (1) fckeditor/editor/filemanager/browser/default/connectors/php/connector.php or (2) fckeditor/editor/dialog/fck_link.php.

    Source:SHiKaA
    Published:19 Sept 2006
    5.1
    Medium

    CVE-2006-4889

    Last Modified: 27 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) index.php, (2) includes/functions.gb.php, (3) includes/functions.admin.php, (4) includes/admin.inc.php, (5) help.php, (6) smile.php, (7) entry.php; (8) adminhelp0.php, (9) adminhelp1.php, (10) adminhelp2.php, and (11) adminhelp3.php in (a) help/en and (b) help/de directories; and the (12) preview.php, (13) log.php, (14) index.php, (15) config.php, and (16) admin.php in the (c) admin directory, a different set of vectors than CVE-2006-4788.

    Source:SHiKaA
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4885

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The bottom.php parameter is already covered by CVE-2006-4826.

    Source:mad_hacker
    Published:19 Sept 2006
    4.3
    Medium

    CVE-2006-4884

    Last Modified: 25 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 allow remote attackers to inject arbitrary web script or HTML via (1) the suser parameter in support/rightbar.php, (2) the ticket_id parameter in support/open_tickets.php, and (3) the cons_page_title parameter in index.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:s3rv3r_hack3r
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4882

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Review.asp in Julian Roberts Charon Cart 3 allows remote attackers to execute arbitrary SQL commands via the ProductID parameter.

    Source:ajann
    Published:19 Sept 2006
    4.3
    Medium

    CVE-2006-4881

    Last Modified: 28 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in David Bennett PHP-Post (PHPp) 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the replyuser parameter in (a) pm.php; (2) the txt_jumpto parameter in (b) dropdown.php; the (3) txt_error and (4) txt_templatenotexist parameters in (c) template.php; the (5) split parameter in certain files, as demonstrated by (d) editprofile.php, (e) search.php, (f) index.php, and (g) pm.php; and the (6) txt_login parameter in (h) loginline.php; and allow remote authenticated users to inject arbitrary web script or HTML via the (7) txt_logout parameter in (i) loginline.php.

    Source:HACKERS PAL
    Published:19 Sept 2006
    5
    Medium

    CVE-2006-4877

    Last Modified: 28 Sept 2013

    Variable overwrite vulnerability in David Bennett PHP-Post (PHPp) 1.0 and earlier allows remote attackers to overwrite arbitrary program variables via multiple vectors that use the extract function, as demonstrated by the table_prefix parameter in (1) index.php, (2) profile.php, and (3) header.php.

    Source:HACKERS PAL
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4876

    Last Modified: 28 Sept 2013

    Multiple SQL injection vulnerabilities in Jupiter CMS allow remote attackers to execute arbitrary SQL commands via (1) the user name during login, or the (2) key or (3) fpwusername parameters in modules/register.

    Source:HACKERS PAL
    Published:19 Sept 2006
    5
    Medium

    CVE-2006-4875

    Last Modified: 28 Sept 2013

    Unrestricted file upload vulnerability in modules/galleryuploadfunction.php in Jupiter CMS allows remote attackers to upload picture files, and possibly files with arbitrary extensions, to gallery/albums/public.

    Source:HACKERS PAL
    Published:19 Sept 2006
    4.3
    Medium

    CVE-2006-4874

    Last Modified: 28 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Jupiter CMS allow remote attackers to inject arbitrary web script or HTML via the (1) language[Admin name] and (2) language[Admin back] parameters in (a) modules/blocks.php; the (3) language[Register title] and (4) language[Register title2] parameters in (b) modules/register.php; the (5) language[Mass-Email form title], (6) language[Mass-Email form desc], (7) language[Mass-Email form desc2] (8) language[Mass-Email form desc3], and (9) language[Mass-Email form desc4] parameters in (c) modules/mass-email.php; the (10) language[Forgotten title], (11) language[Forgotten desc], (12) language[Forgotten desc2], (13) language[Forgotten desc3], (14) language[Forgotten desc4], and (15) language[Forgotten desc5] parameters in (d) modules/register.php; and the (16) language[Search view desc], (17) language[Search view desc2], (18) language[Search view desc3], (19) language[Search view desc4], (20) language[Search view desc5], (21) language[Search view desc6], (22) language[Search view desc7], and (23) language[Search view desc8] parameters in (e) modules/search.php.

    Source:HACKERS PAL
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4872

    Last Modified: 28 Sept 2013

    SQL injection vulnerability in search.asp in Keyvan1 (aka Keyvan Janghorbani) ECardPro 2.0 allows remote attackers to execute arbitrary SQL commands via the keyword parameter.

    Source:ajann
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4871

    Last Modified: 29 Sept 2013

    SQL injection vulnerability in search_run.asp in Keyvan1 (aka Keyvan Janghorbani) EShoppingPro 1.0 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Source:ajann
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4870

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AEDating 4.1, and possibly earlier versions, allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/design.inc.php or (2) inc/admin_design.inc.php.

    Source:NeXtMaN
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4869

    Last Modified: 21 Nov 2016

    PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute arbitrary PHP code via a URL in the gallery_path parameter.

    Source:Rivertam
    Published:19 Sept 2006
    9.3
    Critical

    CVE-2006-4868

    Last Modified: 12 Sept 2016

    Stack-based buffer overflow in the Vector Graphics Rendering engine (vgx.dll), as used in Microsoft Outlook and Internet Explorer 6.0 on Windows XP SP2, and possibly other versions, allows remote attackers to execute arbitrary code via a Vector Markup Language (VML) file with a long fill parameter within a rect tag.

    Source:jamikazu
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4867

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL commands via the t_id parameter when the go parameter is "Forum."

    Source:p2y
    Published:19 Sept 2006
    4.6
    Medium

    CVE-2006-4866

    Last Modified: 27 Sept 2013

    Buffer overflow in kextload in Apple OS X, as used by TDIXSupport in Roxio Toast Titanium and possibly other products, allows local users to execute arbitrary code via a long extension argument.

    Source:Adriel T. Desautels
    Published:19 Sept 2006
    5
    Medium

    CVE-2006-4865

    Last Modified: 9 Sept 2016

    Walter Beschmout PhpQuiz allows remote attackers to obtain sensitive information via a direct request to cfgphpquiz/install.php and other unspecified vectors.

    Source:simo64
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4859

    Last Modified: 10 Nov 2016

    Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mambo) CMS 1.0.4.2L and earlier allows remote attackers to upload PHP code to the images/contact folder via a filename with a double extension in the contact_attach parameter in a contact option in index.php, which bypasses an insufficiently restrictive regular expression.

    Source:rgod
    Published:19 Sept 2006
    6.8
    Medium

    CVE-2006-4858

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4857

    Last Modified: 27 Sept 2013

    SQL injection vulnerability in default.asp (aka the login page) in ClickTech ClickBlog 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) form_codeword (aka the Password field) parameters.

    Source:ajann
    Published:19 Sept 2006
    4.9
    Medium

    CVE-2006-4855

    Last Modified: 11 Oct 2013

    The \Device\SymEvent driver in Symantec Norton Personal Firewall 2006 9.1.0.33, and other versions of Norton Personal Firewall, Internet Security, AntiVirus, SystemWorks, Symantec Client Security SCS 1.x, 2.x, 3.0, and 3.1, Symantec AntiVirus Corporate Edition SAVCE 8.x, 9.x, 10.0, and 10.1, Symantec pcAnywhere 11.5 only, and Symantec Host, allows local users to cause a denial of service (system crash) via invalid data, as demonstrated by calling DeviceIoControl to send the data.

    Source:David Matousek
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4853

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in kategorihaberx.asp.

    Source:Fix TR
    Published:19 Sept 2006