7.5
    High

    CVE-2006-4296

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allows remote attackers to include arbitrary files via the mosConfig_absolute_path parameter.

    Source:mdx
    Published:23 Aug 2006
    4.3
    Medium

    CVE-2006-4295

    Last Modified: 18 Sept 2013

    Cross-site scripting (XSS) vulnerability in ascan_6.asp in Panda ActiveScan 5.53.00 allows remote attackers to inject arbitrary web script or HTML via the email parameter.

    Source:Lostmon
    Published:23 Aug 2006
    5
    Medium

    CVE-2006-4294

    Last Modified: 24 Sept 2013

    Directory traversal vulnerability in viewfile in TWiki 4.0.0 through 4.0.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Peter Thoeny
    Published:9 Sept 2006
    4.3
    Medium

    CVE-2006-4293

    Last Modified: 21 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.

    Source:preth00nker
    Published:22 Aug 2006
    5.1
    Medium

    CVE-2006-4291

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in handlers/email/mod.listmail.php in PHlyMail Lite 3.4.4 and earlier (Build 3.04.04) allows remote attackers to execute arbitrary PHP code via a URL in the _PM_[path][handler] parameter.

    Source:Kacper
    Published:22 Aug 2006
    6.8
    Medium

    CVE-2006-4288

    Last Modified: 7 Oct 2017

    PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits) 2.0.0 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter. NOTE: some of these details are obtained from third party information.

    Source:Cmaster4
    Published:22 Aug 2006
    7.5
    High

    CVE-2006-4287

    Last Modified: 7 Oct 2017

    Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) phphtmllib parameter to (a) phphtmllib/includes.php; tag_utils/ scripts including (b) divtag_utils.php, (c) form_utils.php, (d) html_utils.php, and (e) localinc.php; and widgets/ scripts including (f) FooterNav.php, (g) HTMLPageClass.php, (h) InfoTable.php, (i) localinc.php, (j) NavTable.php, and (k) TextNav.php.

    Source:Kacper
    Published:22 Aug 2006
    7.5
    High

    CVE-2006-4285

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[script_path] parameter. NOTE: it was later reported that 2.1.5 is also affected.

    Source:SHiKaA
    Published:22 Aug 2006
    7.5
    High

    CVE-2006-4284

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Chironex Fleckeri
    Published:22 Aug 2006
    7.5
    High

    CVE-2006-4282

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in MamboLogin.php in the MamboWiki component (com_mambowiki) 0.9.6 and earlier for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the IP parameter.

    Source:camino
    Published:22 Aug 2006
    7.5
    High

    CVE-2006-4279

    Last Modified: 20 Sept 2013

    SQL injection vulnerability in topic_post.php in XennoBB 2.2.1 and earlier allows remote attackers to execute arbitrary SQL commands via the icon_topic parameter.

    Source:Chris Boulton
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4278

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the mainnav parameter.

    Source:Kacper
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4277

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Tutti Nova 1.6 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to (1) include/novalib/class.novaAdmin.mysql.php and (2) novalib/class.novaRead.mysql.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:SHiKaA
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4276

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the TNLIB_DIR parameter to novalib/class.novaEdit.mysql.php.

    Source:SHiKaA
    Published:21 Aug 2006
    6.8
    Medium

    CVE-2006-4273

    Last Modified: 17 Sept 2013

    Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin 3.5.4 and 3.6.0 allows remote attackers to inject arbitrary web script or HTML by uploading an attachment with a .pdf extension that contains JavaScript, which is processed as script by Microsoft Internet Explorer 6.

    Source:imei
    Published:21 Aug 2006
    6.8
    Medium

    CVE-2006-4270

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:mdx
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4267

    Last Modified: 9 Sept 2016

    Multiple SQL injection vulnerabilities in CubeCart 3.0.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) oid parameter in modules/gateway/Protx/confirmed.php and the (2) x_invoice_num parameter in modules/gateway/Authorize/confirmed.php.

    Source:rgod
    Published:21 Aug 2006
    Low

    CVE-2006-4261

    Last Modified: 19 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4253. Reason: This candidate is a duplicate of CVE-2006-4253. Notes: All CVE users should reference CVE-2006-4253 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Michal Zalewski
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4254

    Last Modified: 30 Jan 2017

    Unspecified vulnerability in setlocale in IBM AIX 5.1.0 through 5.3.0 allows local users to gain privileges via unspecified vectors.

    Source:Thomas Pollet
    Published:21 Aug 2006
    7.6
    High

    CVE-2006-4253

    Last Modified: 24 Sept 2013

    Concurrency vulnerability in Mozilla Firefox 1.5.0.6 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via multiple Javascript timed events that load a deeply nested XML file, followed by redirecting the browser to another page, which leads to a concurrency failure that causes structures to be freed incorrectly, as demonstrated by (1) ffoxdie and (2) ffoxdie3. NOTE: it has been reported that Netscape 8.1 and K-Meleon 1.0.1 are also affected by ffoxdie. Mozilla confirmed to CVE that ffoxdie and ffoxdie3 trigger the same underlying vulnerability. NOTE: it was later reported that Firefox 2.0 RC2 and 1.5.0.7 are also affected.

    Source:Michal Zalewski
    Published:12 Aug 2006
    4.6
    Medium

    CVE-2006-4250

    Last Modified: 26 Nov 2013

    Buffer overflow in man and mandb (man-db) 2.4.3 and earlier allows local users to execute arbitrary code via crafted arguments to the -H flag.

    Source:Daniel Roethlisberger
    Published:10 Apr 2007
    5.1
    Medium

    CVE-2006-4242

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Mehmet Ince
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4241

    Last Modified: 20 Sept 2013

    PHP remote file inclusion vulnerability in processor/reporter.sql.php in the Reporter Mambo component (com_reporter) allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Crackers_Child
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4240

    Last Modified: 20 Sept 2013

    PHP remote file inclusion vulnerability in index.php in Fusion News 3.7 allows remote attackers to execute arbitrary PHP code via a URL in the fpath parameter.

    Source:O.U.T.L.A.W
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4239

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in include/urights.php in Outreach Project Tool (OPT) Max 1.2.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CRM_inc parameter.

    Source:Kacper
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4238

    Last Modified: 9 Sept 2016

    SQL injection vulnerability in torrents.php in WebTorrent (WTcom) 0.2.4 and earlier allows remote attackers to execute arbitrary SQL commands via the cat parameter in category mode.

    Source:sh1r081
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4237

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in pageheaderdefault.inc.php in Invisionix Roaming System Remote (IRSR) 0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _sysSessionPath parameter.

    Source:Kacper
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4236

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via a URL in the (1) shopid parameter to (a) s01.php, (b) s02.php, (c) s03.php, and (d) s04.php; and possibly a URL located after "shopid=" or "sid=" in the PATH_INFO.

    Source:Saudi Hackrz
    Published:21 Aug 2006
    7.5
    High

    CVE-2006-4234

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the baseDir parameter.

    Source:Kacper
    Published:18 Aug 2006
    7.5
    High

    CVE-2006-4230

    Last Modified: 19 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in index.php in Lizge V.20 Web Portal allow remote attackers to execute arbitrary PHP code via a URL in the (1) lizge or (2) bade parameters.

    Source:Crackers_Child
    Published:18 Aug 2006
    6.5
    Medium

    CVE-2006-4227

    Last Modified: 20 Sept 2013

    MySQL before 5.0.25 and 5.1 before 5.1.12 evaluates arguments of suid routines in the security context of the routine's definer instead of the routine's caller, which allows remote authenticated users to gain privileges through a routine that has been made available using GRANT EXECUTE.

    Source:Michal Prokopiuk
    Published:29 Mar 2006
    4.3
    Medium

    CVE-2006-4220

    Last Modified: 21 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in webacc in Novell GroupWise WebAccess before 7 Support Pack 3 Public Beta allow remote attackers to inject arbitrary web script or HTML via the (1) User.html, (2) Error, (3) User.Theme.index, and (4) and User.lang parameters.

    Source:Frederic Loudet
    Published:31 Dec 2006
    7.5
    High

    CVE-2006-4219

    Last Modified: 20 Sept 2013

    The Terminal Services COM object (tsuserex.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code by instantiating it as an ActiveX object in Internet Explorer 6.0 SP1 on Microsoft Windows 2003 EE SP1 CN.

    Source:nop
    Published:18 Aug 2006
    7.5
    High

    CVE-2006-4217

    Last Modified: 9 Sept 2016

    PHP remote file inclusion vulnerability in modules/usersonline/users.php in WEBInsta CMS 0.3.1 allows remote attackers to execute arbitrary PHP code via a URL in the module_dir parameter, a different vulnerability than CVE-2006-4196. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Yns
    Published:17 Aug 2006
    Low

    CVE-2006-4216

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4159. Reason: This candidate is a duplicate of CVE-2006-4159. Notes: All CVE users should reference CVE-2006-4159 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Drago84
    Published:17 Aug 2006
    5.1
    Medium

    CVE-2006-4215

    Last Modified: 5 Jan 2018

    PHP remote file inclusion vulnerability in index.php in Zen Cart 1.3.0.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the autoLoadConfig[999][0][loadFile] parameter.

    Source:GulfTech Security
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4213

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in config.php in David Kent Norman Thatware 0.4.6 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:Drago84
    Published:17 Aug 2006
    2.6
    Low

    CVE-2006-4210

    Last Modified: 1 Sept 2016

    nu_mail.inc.php in Andreas Kansok phPay 2.02 and 2.02.1, when register_globals is enabled, allows remote attackers to use the server as an open mail relay via modified mail_text2, user_row[5], nu_mail_1, and shop_mail parameters. NOTE: some of these details are obtained from third party information.

    Source:beford
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4209

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in install3.php in WEBInsta Mailing List Manager 1.3e allows remote attackers to execute arbitrary PHP code via a URL in the cabsolute_path parameter.

    Source:Philipp Niedziela
    Published:17 Aug 2006
    5
    Medium

    CVE-2006-4208

    Last Modified: 19 Sept 2013

    Directory traversal vulnerability in wp-db-backup.php in Skippy WP-DB-Backup plugin for WordPress 1.7 and earlier allows remote authenticated users with administrative privileges to read arbitrary files via a .. (dot dot) in the backup parameter to edit.php.

    Source:marc & shb
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4207

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the fileloc parameter to (1) content/content.php or (2) /inc/indexhead.php.

    Source:Arash RJ
    Published:17 Aug 2006
    4.3
    Medium

    CVE-2006-4206

    Last Modified: 5 Oct 2013

    Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.

    Source:MizoZ
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4205

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter to /classes/ scripts including (1) Cache.class.php, (2) Customer.class.php, (3) Performance.class.php, (4) Project.class.php, (5) Representative.class.php, (6) User.class.php, or (7) common.php.

    Source:the master
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4204

    Last Modified: 9 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in PHProjekt 5.1 and possibly earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) path_pre parameter in lib/specialdays.php and the (2) lib_path parameter in lib/dbman_filter.inc.php.

    Source:Kacper
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4203

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:mdx
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4202

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in proje_goster.php in Spidey Blog Script 1.5 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter.

    Source:ASIANEAGLE
    Published:17 Aug 2006
    5.1
    Medium

    CVE-2006-4198

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in includes/session.php in Wheatblog (wB) 1.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the wb_class_dir parameter.

    Source:O.U.T.L.A.W
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4197

    Last Modified: 24 Sept 2013

    Multiple buffer overflows in libmusicbrainz (aka mb_client or MusicBrainz Client Library) 2.1.2 and earlier, and SVN 8406 and earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via (1) a long Location header by the HTTP server, which triggers an overflow in the MBHttp::Download function in lib/http.cpp; and (2) a long URL in RDF data, as demonstrated by a URL in an rdf:resource field in an RDF XML document, which triggers overflows in many functions in lib/rdfparse.c.

    Source:Luigi Auriemma
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4196

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers to execute arbitrary PHP code via a URL in the templates_dir parameter.

    Source:K-159
    Published:17 Aug 2006
    6.8
    Medium

    CVE-2006-4195

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in param.peoplebook.php in the Peoplebook Component for Mambo (com_peoplebook) 1.0 and earlier, and possibly 1.1.2, when register_globals and allow_url_fopen are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:17 Aug 2006