7.5
    High

    CVE-2006-4720

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary PHP code via a URL in the path_to_folder parameter.

    Source:Solpot
    Published:12 Sept 2006
    5.1
    Medium

    CVE-2006-4719

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the base parameter to (1) index.php or (2) pop.php.

    Source:ddoshomo
    Published:12 Sept 2006
    7.5
    High

    CVE-2006-4716

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the racine parameter.

    Source:ddoshomo
    Published:12 Sept 2006
    7.5
    High

    CVE-2006-4715

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:MercilessTurk
    Published:12 Sept 2006
    5.1
    Medium

    CVE-2006-4714

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the classified_path parameter.

    Source:MercilessTurk
    Published:12 Sept 2006
    7.5
    High

    CVE-2006-4713

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

    Source:Philipp Niedziela
    Published:12 Sept 2006
    5
    Medium

    CVE-2006-4709

    Last Modified: 23 Dec 2016

    SQL injection vulnerability in topic.php in Vikingboard 0.1b allows remote attackers to execute arbitrary SQL commands via the s parameter.

    Source:Hessam-x
    Published:12 Sept 2006
    6.8
    Medium

    CVE-2006-4708

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Vikingboard 0.1b allow remote attackers to inject arbitrary web script or HTML via the (1) act parameter in (a) help.php and (b) search.php, and the (2) p parameter in report.php.

    Source:Hessam-x
    Published:12 Sept 2006
    6.8
    Medium

    CVE-2006-4704

    Last Modified: 18 Nov 2016

    Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."

    Source:Metasploit
    Published:1 Nov 2006
    10
    Critical

    CVE-2006-4691

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

    Source:Winny Thomas
    Published:14 Nov 2006
    7.5
    High

    CVE-2006-4688

    Last Modified: 7 Mar 2011

    Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."

    Source:Metasploit
    Published:14 Nov 2006
    5
    Medium

    CVE-2006-4681

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary files via a .. (dot dot) sequence in the file parameter.

    Source:Daniel Clemens
    Published:11 Sept 2006
    7.5
    High

    CVE-2006-4678

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code via the _NE[AbsPath] parameter in (1) install.php and (2) migrateNE2toNE3.php.

    Source:ddoshomo
    Published:11 Sept 2006
    1.2
    Low

    CVE-2006-4676

    Last Modified: 16 Apr 2026

    TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to obtain sensitive information by decoding the log file.

    Source:Andres Tarasco
    Published:11 Sept 2006
    2.6
    Low

    CVE-2006-4673

    Last Modified: 22 Nov 2016

    Global variable overwrite vulnerability in maincore.php in PHP-Fusion 6.01.4 and earlier uses the extract function on the superglobals, which allows remote attackers to conduct SQL injection attacks via the _SERVER[REMOTE_ADDR] parameter to news.php.

    Source:rgod
    Published:11 Sept 2006
    7.5
    High

    CVE-2006-4672

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote attackers to execute arbitrary PHP code via a URL in the (1) proMod parameter to (a) index.php, or the (2) docroot parameter to (b) index.php or (c) mainpage.php.

    Source:momo26
    Published:11 Sept 2006
    6.8
    Medium

    CVE-2006-4671

    Last Modified: 20 Sept 2016

    PHP remote file inclusion vulnerability in headlines.php in Fantastic News 2.1.4, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter, a different vector than CVE-2006-1154.

    Source:Mr-m07
    Published:11 Sept 2006
    7.5
    High

    CVE-2006-4670

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PhotoKorn Gallery 1.52 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the dir_path parameter in (1) includes/cart.inc.php or (2) extras/ext_cats.php.

    Source:Saudi Hackrz
    Published:9 Sept 2006
    5.1
    Medium

    CVE-2006-4669

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the skindir parameter.

    Source:basher13
    Published:9 Sept 2006
    4.3
    Medium

    CVE-2006-4668

    Last Modified: 24 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in Rob Hensley AckerTodo 4.0 allows remote attackers to inject arbitrary web script or HTML via the task_id parameter in an edit_task command.

    Source:viz.security
    Published:9 Sept 2006
    7.5
    High

    CVE-2006-4666

    Last Modified: 2 Jan 2014

    Multiple PHP remote file inclusion vulnerabilities in Stefan Ernst Newsscript (aka WM-News) 0.5 beta allow remote attackers to execute arbitrary PHP code via a URL in the (1) ide parameter in (a) article.php; or the (2) pwfile parameter in (b) delete.php, (c) modify.php, (d) admin.php, or (e) modify_go.php.

    Source:osm
    Published:9 Sept 2006
    5.1
    Medium

    CVE-2006-4664

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Kw3[R]Ln
    Published:9 Sept 2006
    7.5
    High

    CVE-2006-4656

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter. NOTE: CVE analysis suggests that this issue is actually in a third party product, SPAW Editor PHP Edition.

    Source:v1per-haCker
    Published:9 Sept 2006
    4.6
    Medium

    CVE-2006-4655

    Last Modified: 27 Oct 2016

    Buffer overflow in the Strcmp function in the XKEYBOARD extension in X Window System X11R6.4 and earlier, as used in SCO UnixWare 7.1.3 and Sun Solaris 8 through 10, allows local users to gain privileges via a long _XKB_CHARSET environment variable value.

    Source:RISE Security
    Published:9 Sept 2006
    5.1
    Medium

    CVE-2006-4654

    Last Modified: 23 Sept 2013

    Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (crash) or "compromise the server" via encoded format string specifiers in the query string.

    Source:Revnic Vasile
    Published:9 Sept 2006
    7.5
    High

    CVE-2006-4649

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4648

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the bnrep parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4647

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sndir parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4645

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in akarru.gui/main_content.php in Akarru Social BookMarking Engine 0.4.3.34 and earlier, and possibly 0.4.4.120, allows remote attackers to execute arbitrary PHP code via a URL in the bm_content parameter.

    Source:ddoshomo
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4644

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in modules/home.module.php in phpFullAnnu 5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the repmod parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4643

    Last Modified: 24 Sept 2013

    SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to execute arbitrary SQL commands via the id_joueur parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:DrEiNsTeIn
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4641

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary SQL commands via the kat parameter.

    Source:ASIANEAGLE
    Published:8 Sept 2006
    5.1
    Medium

    CVE-2006-4638

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    5.1
    Medium

    CVE-2006-4637

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in ACGV News 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the PathNews parameter in (1) header.php or (2) news.php. NOTE: portions of these details are obtained from third party information.

    Source:ddoshomo
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4636

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the Directory parameter, as demonstrated by parameter values naming Apache HTTP Server log files that apparently contain PHP code.

    Source:Kacper
    Published:8 Sept 2006
    4.3
    Medium

    CVE-2006-4634

    Last Modified: 23 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script or HTML via the UserID parameter, a different vector than CVE-2006-1133 and CVE-2005-2441.

    Source:Crack_MaN
    Published:8 Sept 2006
    5
    Medium

    CVE-2006-4633

    Last Modified: 16 Apr 2026

    index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or invalid page[] parameter.

    Source:DarkFig
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4632

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary SQL commands via the (1) groupe parameter in addmembre.php and the (2) select parameter in moveto.php.

    Source:DarkFig
    Published:8 Sept 2006
    6.5
    Medium

    CVE-2006-4631

    Last Modified: 23 Sept 2013

    Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote authenticated users to upload and execute arbitrary PHP code via the cache_forum parameter, which saves the code to info_options.php, which is accessible via a direct request.

    Source:Kacper
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4630

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the my_ms[root] parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    7.5
    High

    CVE-2006-4629

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:SHiKaA
    Published:8 Sept 2006
    3.6
    Low

    CVE-2006-4625

    Last Modified: 2 Dec 2016

    PHP 4.x up to 4.4.4 and PHP 5 up to 5.1.6 allows local users to bypass certain Apache HTTP Server httpd.conf options, such as safe_mode and open_basedir, via the ini_restore function, which resets the values to their php.ini (Master Value) defaults.

    Source:Maksymilian Arciemowicz
    Published:9 Sept 2006
    7.5
    High

    CVE-2006-4622

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Kurdish Security
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4612

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands via the RepId parameter.

    Source:Chironex Fleckeri
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4611

    Last Modified: 23 Sept 2013

    Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long node name.

    Source:Michael Adams
    Published:7 Sept 2006
    5.1
    Medium

    CVE-2006-4610

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the page parameter.

    Source:Kurdish Security
    Published:7 Sept 2006
    5.1
    Medium

    CVE-2006-4609

    Last Modified: 21 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in the Content Management module ("Content manager") for PHProjekt 0.6.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via the path_pre parameter in (1) cm_lib.inc.php, (2) doc/br.edithelp.php, (3) doc/de.edithelp.php, (4) doc/ct.edithelp.php, (5) userrating.php, and (6) listing.php, a different set of vectors than CVE-2006-4204. NOTE: a third-party researcher has disputed the impact of the cm_lib.inc.php vector, stating that it is limited to local file inclusion. CVE analysis as of 20060905 concurs, although use of ftp URLs is also possible. The remaining five vectors have also been disputed by the same third party, stating that the path_pre variable is initialized before it is used

    Source:the master
    Published:7 Sept 2006
    6.8
    Medium

    CVE-2006-4608

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) cadena parameter in busqueda.php and the (2) email parameter in lista.php.

    Source:SirDarckCat
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4607

    Last Modified: 16 Apr 2026

    admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting the ID_ADMIN and SUPER_ADMIN parameters to 1.

    Source:SirDarckCat
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4606

    Last Modified: 30 Sept 2016

    Multiple SQL injection vulnerabilities in Longino Jacome php-Revista 1.1.2 allow remote attackers to execute arbitrary SQL commands via the (1) id_temas parameter in busqueda_tema.php, the (2) cadena parameter in busqueda.php, the (3) id_autor parameter in autor.php, the (4) email parameter in lista.php, and the (5) id_articulo parameter in articulo.php.

    Source:Cold Zero
    Published:7 Sept 2006