7.5
    High

    CVE-2006-4852

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL commands via the OrderBy parameter.

    Source:ajann
    Published:19 Sept 2006
    5.1
    Medium

    CVE-2006-4850

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the gBRootPath parameter.

    Source:Mehmet Ince
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4849

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in header.php in MobilePublisherPHP 1.5 RC2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.

    Source:Timq
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-4848

    Last Modified: 28 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in Brian Fraval Hitweb 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REP_CLASS parameter to (1) index.php, (2) arbo.php, (3) framepoint.php, (4) genpage.php, (5) lienvalider.php, (6) appreciation.php, (7) partenariat.php, (8) rechercher.php, (9) projet.php, (10) propoexample.php, (11) refererpoint.php, or (12) top50.php. NOTE: this issue has been disputed by a third party researcher, stating that REP_CLASS is initialized in an included file before being used

    Source:ERNE
    Published:19 Sept 2006
    6.5
    Medium

    CVE-2006-4847

    Last Modified: 27 Oct 2016

    Multiple buffer overflows in Ipswitch WS_FTP Server 5.05 before Hotfix 1 allow remote authenticated users to execute arbitrary code via long (1) XCRC, (2) XSHA1, or (3) XMD5 commands.

    Source:Metasploit
    Published:19 Sept 2006
    5.1
    Medium

    CVE-2006-4845

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tc_config[app_root] parameter.

    Source:PSYCH@
    Published:19 Sept 2006
    5.1
    Medium

    CVE-2006-4844

    Last Modified: 19 Jan 2018

    PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeos and possibly other products, allows remote attackers to execute arbitrary PHP code via a URL in the extAuthSource[newUser] parameter.

    Source:GulfTech Security
    Published:19 Sept 2006
    3.6
    Low

    CVE-2006-4842

    Last Modified: 18 Sept 2018

    The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment variables for specifying log files even when running from setuid programs, which allows local users to create or overwrite arbitrary files.

    Source:Metasploit
    Published:5 Sept 2006
    4.3
    Medium

    CVE-2006-4838

    Last Modified: 27 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal SE 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) root_url and (2) dcp_version parameters in (a) admin/inc/footer.inc.php, and the root_url, (3) page_top_name, (4) page_name, and (5) page_options parameters in (b) admin/inc/header.inc.php.

    Source:HACKERS PAL
    Published:15 Sept 2006
    5.1
    Medium

    CVE-2006-4836

    Last Modified: 27 Sept 2013

    SQL injection vulnerability in login.php in DCP-Portal SE 6.0 allows remote attackers to execute arbitrary SQL commands via the username parameter. NOTE: The lostpassword.php and calendar.php vectors are already covered by CVE-2005-3365, and the search.php vector is already covered by CVE-2005-4227.

    Source:HACKERS PAL
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4834

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in index.php in Jule Slootbeek phpQuiz 0.01 allows remote attackers to execute arbitrary PHP code via a URL in the pagename parameter.

    Source:Solpot
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4832

    Last Modified: 25 Sept 2013

    Buffer overflow in the telnet service in Verso NetPerformer FRAD ACT SDM-95xx 7.xx (R1) and earlier, SDM-93xx 10.x.x (R2) and earlier, and SDM-92xx 9.x.x (R1) and earlier allows remote attackers to cause a denial of service (reboot) and possibly execute arbitrary code via a long username.

    Source:Arif Jatmoko
    Published:15 Sept 2006
    6.8
    Medium

    CVE-2006-4829

    Last Modified: 27 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in David Czarnecki Blojsom 2.31 allow remote attackers to inject arbitrary web script or HTML via the (1) blog-category-description, (2) blog-entry-title, (3) rss-enclosure-url, (4) technorati-tagsi, or (5) blog-category-name parameter in a blog post.

    Source:Avinash Shenoi
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4828

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in zipndownload.php in PhotoPost 4.0 through 4.6 allows remote attackers to execute arbitrary PHP code via a URL in the PP_PATH parameter.

    Source:Saudi Hackrz
    Published:15 Sept 2006
    5.1
    Medium

    CVE-2006-4827

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the art parameter to (1) admin.php, (2) chart.php, (3) modes.php, or (4) stats.php.

    Source:SilenZ
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4826

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:mad_hacker
    Published:15 Sept 2006
    4.3
    Medium

    CVE-2006-4825

    Last Modified: 27 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cl_files/index.php in SoftComplex PHP Event Calendar 1.5.1, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) ti, (2) bi, or (3) cbgi parameters.

    Source:NR Nandini
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4824

    Last Modified: 15 Dec 2016

    PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the set[include_path] parameter.

    Source:mdx
    Published:15 Sept 2006
    7.5
    High

    CVE-2006-4823

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter.

    Source:Saudi Hackrz
    Published:15 Sept 2006
    4.6
    Medium

    CVE-2006-4814

    Last Modified: 23 Apr 2026

    The mincore function in the Linux kernel before 2.4.33.6 does not properly lock access to user space, which has unspecified impact and attack vectors, possibly related to a deadlock.

    Published:14 Dec 2006
    10
    Critical

    CVE-2006-4812

    Last Modified: 2 Dec 2016

    Integer overflow in PHP 5 up to 5.1.6 and 4 before 4.3.0 allows remote attackers to execute arbitrary code via an argument to the unserialize PHP function with a large value for the number of array elements, which triggers the overflow in the Zend Engine ecalloc function (Zend/zend_alloc.c).

    Source:anonymous
    Published:30 Sept 2006
    4.3
    Medium

    CVE-2006-4796

    Last Modified: 27 Sept 2013

    Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).

    Source:ajann
    Published:14 Sept 2006
    4.3
    Medium

    CVE-2006-4794

    Last Modified: 25 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the query string (PATH_INFO) in (1) contact.php, (2) download.php, (3) admin.php, (4) fpw.php, (5) news.php, (6) search.php, (7) signup.php, (8) submitnews.php, and (9) user.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:zark0vac
    Published:14 Sept 2006
    7.5
    High

    CVE-2006-4793

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL commands, as demonstrated by the icerikno parameter.

    Source:RMx
    Published:14 Sept 2006
    4.6
    Medium

    CVE-2006-4789

    Last Modified: 9 Sept 2016

    Buffer overflow in Open Movie Editor 0.0.20060901 allows local users to cause a denial of service (system crash) or execute arbitrary code via a long project name in an open_movie_editor_project XML tag.

    Source:Qnix
    Published:14 Sept 2006
    5.1
    Medium

    CVE-2006-4788

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, when register_globals is enabled and _SESSION[permission] parameter is set to "yes", allows remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter.

    Source:SHiKaA
    Published:14 Sept 2006
    5.4
    Medium

    CVE-2006-4782

    Last Modified: 16 Apr 2026

    src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication and gain sensitive information stored in the database via a modified userID parameter in a write action to admin/database.php.

    Source:Trex
    Published:14 Sept 2006
    7.5
    High

    CVE-2006-4781

    Last Modified: 29 Sept 2016

    Heap-based buffer overflow in FutureSoft TFTP Server Multithreaded (MT) 1.1 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code by sending a crafted packet to port 69/UDP, which triggers the overflow when constructing an absolute path name. NOTE: Some details are obtained from third party information.

    Source:n00b
    Published:14 Sept 2006
    7.5
    High

    CVE-2006-4780

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:AzzCoder
    Published:14 Sept 2006
    7.5
    High

    CVE-2006-4779

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_portal.php in Vitrax Premodded phpBB 1.0.6-R3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:CeNGiZ-HaN
    Published:14 Sept 2006
    7.6
    High

    CVE-2006-4777

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the DirectAnimation Path Control (DirectAnimation.PathControl) COM object (daxctle.ocx) for Internet Explorer 6.0 SP1, on Chinese and possibly other Windows distributions, allows remote attackers to execute arbitrary code via unknown manipulations in arguments to the KeyFrame method, possibly related to an integer overflow, as demonstrated by daxctle2, and a different vulnerability than CVE-2006-4446.

    Source:nop
    Published:14 Sept 2006
    4.3
    Medium

    CVE-2006-4771

    Last Modified: 25 Sept 2013

    Cross-site scripting (XSS) vulnerability in haut.php in ForumJBC 4 allows remote attackers to inject arbitrary web script or HTML via the nb_connecte parameter.

    Source:ThE__LeO
    Published:14 Sept 2006
    7.5
    High

    CVE-2006-4770

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in menu.php in MiniPort@l 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the skiny parameter.

    Source:Kacper
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4769

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in abf_js.php in p4CMS 1.05 allows remote attackers to execute arbitrary PHP code via a URL in the abs_pfad parameter.

    Source:SHiKaA
    Published:13 Sept 2006
    5
    Medium

    CVE-2006-4766

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in print.php in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allows remote attackers to read arbitrary files via a .. (dot dot) in the ide parameter.

    Source:Daftrix Security
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4764

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in common.php in Thomas LETE WTools 0.0.1-ALPH allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:ddoshomo
    Published:13 Sept 2006
    6.8
    Medium

    CVE-2006-4754

    Last Modified: 25 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in PHProg before 1.1 allows remote attackers to inject arbitrary web script or HTML via the album parameter, which is used in an opendir call. NOTE: the same primary issue can be used for full path disclosure with an invalid parameter that reveals the installation path in an error message.

    Source:cdg393
    Published:13 Sept 2006
    5
    Medium

    CVE-2006-4753

    Last Modified: 25 Sept 2013

    Directory traversal vulnerability in index.php in PHProg before 1.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter.

    Source:cdg393
    Published:13 Sept 2006
    6.8
    Medium

    CVE-2006-4751

    Last Modified: 25 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5.1 allows remote attackers to inject arbitrary web script or HTML via the errcode parameter.

    Source:HACKERS PAL
    Published:13 Sept 2006
    5.1
    Medium

    CVE-2006-4750

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the config[openi_dir] parameter.

    Source:basher13
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4749

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers to execute arbitrary PHP code via the include_location parameter in (1) activate.php, (2) configure.php, (3) fileop.php, (4) getimg.php, (5) ipblocked.php, (6) register.php, (7) showrecent.php, (8) showtophits.php, (9) usrmanag.php, (10) viewer_bottom.php, (11) viewer_content.php, and (12) viewer_top.php. NOTE: The login.php and confirm.php vectors are already covered by CVE-2006-4594.

    Source:KinSize
    Published:13 Sept 2006
    4.3
    Medium

    CVE-2006-4747

    Last Modified: 24 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in IdevSpot TextAds allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in delete.php and (2) the error parameter in error.php.

    Source:s3rv3r_hack3r
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4746

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.

    Source:Mehmet Ince
    Published:13 Sept 2006
    4.3
    Medium

    CVE-2006-4742

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in user_add.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:s3rv3r_hack3r
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4741

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bits_listings.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary code via the svr_rootPhpStart parameter.

    Source:s3rv3r_hack3r
    Published:13 Sept 2006
    7.5
    High

    CVE-2006-4733

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in sipssys/code/box.inc.php in Haakon Nilsen simple, integrated publishing system (SIPS) 0.3.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the config[sipssys] parameter. NOTE: the product's documentation recommends placing the affected file outside of the web root, so the scope of issue is limited to admins who do not, or cannot, follow this recommendation.

    Source:ajann
    Published:13 Sept 2006
    5
    Medium

    CVE-2006-4731

    Last Modified: 25 Sept 2013

    Multiple directory traversal vulnerabilities in (1) login.pl and (2) admin.pl in (a) SQL-Ledger before 2.6.19 and (b) LedgerSMB before 1.0.0p1 allow remote attackers to execute arbitrary Perl code via an unspecified terminal parameter value containing ../ (dot dot slash).

    Source:Chris Murtagh
    Published:13 Sept 2006
    5.1
    Medium

    CVE-2006-4723

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in raidenhttpd-admin/slice/check.php in RaidenHTTPD 1.1.49, when register_globals and WebAdmin is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SoftParserFileXml parameter.

    Source:rgod
    Published:12 Sept 2006
    7.5
    High

    CVE-2006-4722

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Open Bulletin Board (OpenBB) 1.0.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) index.php and possibly (2) collector.php.

    Source:Eddy_BAck0o
    Published:12 Sept 2006
    5.1
    Medium

    CVE-2006-4721

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in admin.php in CCleague Pro Sports CMS 1.0.1 RC1 allows remote attackers to read and execute arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the language Cookie parameter, as demonstrated by executing PHP code via a log file.

    Source:Kacper
    Published:12 Sept 2006