7.5
    High

    CVE-2006-4605

    Last Modified: 16 Sept 2016

    PHP remote file inclusion vulnerability in index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to execute arbitrary PHP code via the adodb parameter.

    Source:Cold Zero
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4604

    Last Modified: 14 Sept 2016

    PHP remote file inclusion vulnerability in LFXlib/access_manager.php in Lanifex Database of Managed Objects (DMO) 2.3 Beta and earlier allows remote attackers to execute arbitrary PHP code via the _incMgr parameter.

    Source:Kacper
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4602

    Last Modified: 18 Oct 2016

    Unrestricted file upload vulnerability in jhot.php in TikiWiki 1.9.4 Sirius and earlier allows remote attackers to execute arbitrary PHP code via a filepath parameter that contains a filename with a .php extension, which is uploaded to the img/wiki/ directory.

    Source:rgod
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4601

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:DarkFig
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4599

    Last Modified: 23 Sept 2013

    SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary SQL commands via the user parameter.

    Source:SirDarckCat
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4597

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the YID parameter.

    Source:Chironex Fleckeri
    Published:7 Sept 2006
    5.1
    Medium

    CVE-2006-4596

    Last Modified: 16 Apr 2026

    PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) hauptverzeichniss parameter in includes/login_check.php and the (2) template_back parameter in admin/login/content/user_daten.php.

    Source:Philipp Niedziela
    Published:7 Sept 2006
    7.5
    High

    CVE-2006-4594

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpAtm) 1.21 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the include_location parameter in (1) confirm.php or (2) login.php. NOTE: the include_location parameter to index.php is already covered by CVE-2005-1681.

    Source:KinSize
    Published:6 Sept 2006
    6.8
    Medium

    CVE-2006-4593

    Last Modified: 23 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:ThE__LeO
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4592

    Last Modified: 16 Apr 2026

    Incomplete blacklist vulnerability in default.asp in 8pixel.net Simple Blog 2.3 and earlier allows remote attackers to conduct SQL injection attacks via ">" characters in the id parameter, which are not filtered by the protection mechanism.

    Source:Vipsta/MurderSkillz
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4591

    Last Modified: 22 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller Pro 3.25, allow remote attackers to execute arbitrary PHP code via a URL in the config[template_path] parameter to (1) payment/payment_result.php or (2) /payment/spuser_result.php.

    Source:night_warrior771
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4589

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the x_admindir parameter.

    Source:SHiKaA
    Published:6 Sept 2006
    5.5
    Medium

    CVE-2006-4586

    Last Modified: 27 Oct 2016

    The admin panel in Tr Forum 2.0 accepts a username and password hash for authentication, which allows remote authenticated users to perform unauthorized actions, as demonstrated by modifying user settings via the id parameter to /membres/modif_profil.php, and changing a password via /membres/change_mdp.php. NOTE: this can be leveraged with other Tr Forum vulnerabilities to allow unauthenticated attackers to gain privileges.

    Source:DarkFig
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4584

    Last Modified: 16 Apr 2026

    Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and password parameters to admin/insert_admin.php.

    Source:EL-KAHINA
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4583

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) inc/cmses/aedatingCMS.php, (2) inc/cmses/aedatingCMS2.php, or (3) inc/cmses/aedating4CMS.php.

    Source:NeXtMaN
    Published:6 Sept 2006
    6.8
    Medium

    CVE-2006-4563

    Last Modified: 23 Sept 2013

    Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to inject arbitrary web script or HTML via the myh_op parameter to modules.php.

    Source:Thomas Pollet
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4559

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter in (1) articles/populate.php, (2) categories/category.php, (3) categories/populate.php, (4) comments/populate.php, (5) files/file.php, (6) sections/section.php, (7) sections/populate.php, (8) tables/populate.php, (9) users/user.php, and (10) users/populate.php. The articles/article.php vector is covered by CVE-2006-4532.

    Source:MATASANOS
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4558

    Last Modified: 22 Nov 2017

    DeluxeBB 1.06 and earlier, when run on the Apache HTTP Server with the mod_mime module, allows remote attackers to execute arbitrary PHP code by uploading files with double extensions via the fileupload parameter in a newthread action in newpost.php.

    Source:rgod
    Published:6 Sept 2006
    6.8
    Medium

    CVE-2006-4553

    Last Modified: 6 Dec 2016

    PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:6 Sept 2006
    7.5
    High

    CVE-2006-4545

    Last Modified: 22 Sept 2013

    PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP code via the _SERVER parameter in (1) admin/avatar.php, (2) libs/archive.class.php, (3) libs/login.php, (4) libs/profiles.class.php, and (5) libs/profile/proccess.php. NOTE: CVE disputes this claim, as the _SERVER array and the _SERVER[DOCUMENT_ROOT] index are controlled by PHP and cannot be manipulated by an attacker

    Source:sCORPINo
    Published:6 Sept 2006
    6.8
    Medium

    CVE-2006-4543

    Last Modified: 22 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web script or HTML via the (1) game parameter in players mode, the (2) weapon parameter in weaponinfo mode, the (3) st parameter in search mode, the (4) action parameter in actioninfo mode, and the (5) map parameter in mapinfo mode.

    Source:MC.Iglo
    Published:6 Sept 2006
    4.6
    Medium

    CVE-2006-4541

    Last Modified: 11 Oct 2013

    RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a denial of service (crash) via a NULL third argument to the NtOpenSection API function. NOTE: it was later reported that 3.6.cqn is also affected.

    Source:David Matousek
    Published:5 Sept 2006
    6.8
    Medium

    CVE-2006-4540

    Last Modified: 23 Sept 2013

    Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Crack_MaN
    Published:5 Sept 2006
    7.5
    High

    CVE-2006-4536

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in module/rejestracja.php in CMS Frogss 0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the podpis parameter.

    Source:Kacper
    Published:5 Sept 2006
    7.5
    High

    CVE-2006-4532

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in articles/article.php in Yet Another Community System (YACS) CMS 6.6.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the context[path_to_root] parameter.

    Source:MATASANOS
    Published:1 Sept 2006
    7.5
    High

    CVE-2006-4531

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/config.php in Pheap CMS 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lpref parameter.

    Source:Kacper
    Published:1 Sept 2006
    4.3
    Medium

    CVE-2006-4525

    Last Modified: 19 Jan 2018

    Cross-site scripting (XSS) vulnerability in CubeCart 3.0.12 and earlier, when register_globals is enabled, allows remote attackers to inject arbitrary web script or HTML via the links array.

    Source:GulfTech Security
    Published:1 Sept 2006
    7.5
    High

    CVE-2006-4524

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arbitrary SQL commands via the (1) login or (2) password parameters. NOTE: some of these details are obtained from third party information.

    Source:R3d-D3V!L
    Published:1 Sept 2006
    5
    Medium

    CVE-2006-4523

    Last Modified: 16 Apr 2026

    The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote attackers to cause a denial of service (crash) via a CRLF sequence in a GET request.

    Source:preth00nker
    Published:1 Sept 2006
    4.9
    Medium

    CVE-2006-4516

    Last Modified: 12 Oct 2017

    Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and kernel panic) via a PT_LWPINFO ptrace command with a large negative data value that satisfies a signed maximum value check but is used in an unsigned copyout function call.

    Source:kokanin
    Published:12 Oct 2006
    7.5
    High

    CVE-2006-4505

    Last Modified: 27 Sept 2013

    CRLF injection vulnerability in links.php in NX5Linx 1.0 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a CRLF sequence in the url parameter.

    Source:Aliaksandr Hartsuyeu
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4504

    Last Modified: 27 Sept 2013

    SQL injection vulnerability in NX5Linx 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) c and (2) l parameters.

    Source:Aliaksandr Hartsuyeu
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4498

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter, a different vector than CVE-2006-3922.

    Source:Mehmet Ince
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4497

    Last Modified: 22 Sept 2013

    SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Hessam-x
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4495

    Last Modified: 21 Sept 2013

    Microsoft Internet Explorer allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Windows 2000 ActiveX COM Objects including (1) ciodm.dll, (2) myinfo.dll, (3) msdxm.ocx, and (4) creator.dll.

    Source:nop
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4494

    Last Modified: 20 Sept 2013

    Microsoft Visual Studio 6.0 allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code by instantiating certain Visual Studio 6.0 ActiveX COM Objects in Internet Explorer, including (1) tcprops.dll, (2) fp30wec.dll, (3) mdt2db.dll, (4) mdt2qd.dll, and (5) vi30aut.dll.

    Source:XSec
    Published:31 Aug 2006
    4
    Medium

    CVE-2006-4490

    Last Modified: 16 Apr 2026

    Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 allow remote authenticated users to read arbitrary files via a .. (dot dot) sequence via the id parameter in (1) scripts/cbag/ag.exe or (2) scripts/s360v2/s360.exe.

    Source:Tan Chew Keong
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4489

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbitrary PHP code via (1) a URL in the config[include_dir] parameter in actions/ipn.php or (2) an FTP path in the config[plugin_dir] parameter in include/initPlugins.php.

    Source:the master
    Published:31 Aug 2006
    5.1
    Medium

    CVE-2006-4488

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the exbb[home_path] parameter.

    Source:SHiKaA
    Published:31 Aug 2006
    4.3
    Medium

    CVE-2006-4479

    Last Modified: 23 Sept 2013

    Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to inject arbitrary web script or HTML via the subgroupname parameter.

    Source:DarkFig
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4478

    Last Modified: 23 Sept 2013

    SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute arbitrary SQL commands via the groupname parameter.

    Source:DarkFig
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4477

    Last Modified: 27 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute arbitrary PHP code via an empty GLOBALS[rootdp] parameter and an ftps URL in the (1) GLOBALS[admin_home] parameter in (a) diary/event_list.php, (b) gallery/gallery_summary.php, (c) guestbook/showguestbook.php, (d) links/showlinks.php, and (e) reviews/review_summary.php; and the (2) GLOBALS[language_home] parameter in (f) calendar/calendar.php, (g) news/shownews.php, (h) poll/showpoll.php, (i) search/search.php, (j) toprated/toprated.php, and (k) whatsnew/whatsnew.php.

    Source:DarkFig
    Published:31 Aug 2006
    5
    Medium

    CVE-2006-4464

    Last Modified: 16 Apr 2026

    The Nokia Browser, possibly Nokia Symbian 60 Browser 3rd edition, allows remote attackers to cause a denial of service (crash) via JavaScript that constructs a large Unicode string.

    Source:Qode
    Published:31 Aug 2006
    6.4
    Medium

    CVE-2006-4458

    Last Modified: 14 Sept 2016

    Directory traversal vulnerability in calendar/inc/class.holidaycalc.inc.php in phpGroupWare 0.9.16.010 and earlier allows remote attackers to include arbitrary local files via a .. (dot dot) sequence and trailing null (%00) byte in the GLOBALS[phpgw_info][user][preferences][common][country] parameter.

    Source:Kacper
    Published:31 Aug 2006
    7.5
    High

    CVE-2006-4456

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in functions.php in phpECard 2.1.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:LeAk
    Published:31 Aug 2006
    5
    Medium

    CVE-2006-4455

    Last Modified: 27 Apr 2011

    Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via unspecified vectors involving the PRIVMSG command. NOTE: the vendor has disputed this vulnerability, stating that it does not affect 2.6.7 "or any recent version"

    Source:ratboy
    Published:30 Aug 2006
    4.3
    Medium

    CVE-2006-4454

    Last Modified: 22 Sept 2013

    Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:kefka
    Published:30 Aug 2006
    7.5
    High

    CVE-2006-4452

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the PHPSECURITYADMIN_PATH parameter.

    Source:SHiKaA
    Published:30 Aug 2006
    5.1
    Medium

    CVE-2006-4450

    Last Modified: 25 Aug 2013

    usercp_avatar.php in PHPBB 2.0.20, when avatar uploading is enabled, allows remote attackers to use the server as a web proxy by submitting a URL to the avatarurl parameter, which is then used in an HTTP GET request.

    Source:rgod
    Published:30 Aug 2006
    5.1
    Medium

    CVE-2006-4449

    Last Modified: 22 Sept 2013

    Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions allows remote attackers to inject arbitrary web script or HTML via a GIF image that contains URL-encoded Javascript, which is rendered by Internet Explorer.

    Source:Redworm
    Published:30 Aug 2006