7.5
    High

    CVE-2006-4193

    Last Modified: 19 Sept 2013

    Microsoft Internet Explorer 6.0 SP1 and possibly other versions allows remote attackers to cause a denial of service and possibly execute arbitrary code by instantiating COM objects as ActiveX controls, including (1) imskdic.dll (Microsoft IME), (2) chtskdic.dll (Microsoft IME), and (3) msoe.dll (Outlook), which leads to memory corruption. NOTE: it is not certain whether the issue is in Internet Explorer or the individual DLL files.

    Source:nop
    Published:17 Aug 2006
    5.1
    Medium

    CVE-2006-4192

    Last Modified: 1 Sept 2016

    Multiple buffer overflows in MODPlug Tracker (OpenMPT) 1.17.02.43 and earlier and libmodplug 0.8 and earlier, as used in GStreamer and possibly other products, allow user-assisted remote attackers to execute arbitrary code via (1) long strings in ITP files used by the CSoundFile::ReadITProject function in soundlib/Load_it.cpp and (2) crafted modules used by the CSoundFile::ReadSample function in soundlib/Sndfile.cpp, as demonstrated by crafted AMF files.

    Source:Luigi Auriemma
    Published:17 Aug 2006
    5.1
    Medium

    CVE-2006-4191

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in memcp.php in XMB (Extreme Message Board) 1.9.6 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the langfilenew parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by header.php.

    Source:rgod
    Published:17 Aug 2006
    2.1
    Low

    CVE-2006-4190

    Last Modified: 19 Sept 2013

    Directory traversal vulnerability in autohtml.php in the AutoHTML module for PHP-Nuke allows local users to include arbitrary files via a .. (dot dot) in the name parameter for a modload operation.

    Source:MosT3mR
    Published:17 Aug 2006
    7.5
    High

    CVE-2006-4182

    Last Modified: 14 Aug 2017

    Integer overflow in ClamAV 0.88.1 and 0.88.4, and other versions before 0.88.5, allows remote attackers to cause a denial of service (scanning service crash) and execute arbitrary code via a crafted Portable Executable (PE) file that leads to a heap-based buffer overflow when less memory is allocated than expected.

    Source:Damian Put
    Published:16 Oct 2006
    4.9
    Medium

    CVE-2006-4178

    Last Modified: 30 Sept 2013

    Integer signedness error in the i386_set_ldt call in FreeBSD 5.5, and possibly earlier versions down to 5.2, allows local users to cause a denial of service (crash) via unspecified arguments that use negative signed integers to cause the bzero function to be called with a large length parameter, a different vulnerability than CVE-2006-4172.

    Source:Adriano Lima
    Published:26 Sept 2006
    7.5
    High

    CVE-2006-4166

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the image parameter to (1) image.php or (2) image.php2.

    Source:Mehmet Ince
    Published:16 Aug 2006
    7.5
    High

    CVE-2006-4164

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ficStyle parameter.

    Source:Cmaster4
    Published:16 Aug 2006
    7.5
    High

    CVE-2006-4163

    Last Modified: 28 Nov 2016

    PHP remote file inclusion vulnerability in cls_fast_template.php in myWebland miniBloggie 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the fname parameter. NOTE: another researcher was unable to find a way to execute code after including it via a URL. CVE analysis as of 20060816 was inconclusive

    Source:sh3ll
    Published:16 Aug 2006
    5
    Medium

    CVE-2006-4161

    Last Modified: 18 Sept 2013

    Directory traversal vulnerability in the avatar_gallery action in profile.php in XennoBB 2.1.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the category parameter.

    Source:Chris Boulton
    Published:16 Aug 2006
    7.5
    High

    CVE-2006-4160

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Tony Bibbs and Vincent Furia MVCnPHP 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the glConf[path_library] parameter to (1) BaseCommand.php, (2) BaseLoader.php, and (3) BaseView.php.

    Source:Drago84
    Published:16 Aug 2006
    7.5
    High

    CVE-2006-4159

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the _BASE parameter to scripts in Classes/ including (1) Evenement.php, (2) Event.php, (3) Event_for_month.php, (4) Event_for_week.php, (5) My_Log.php, (6) My_Smarty.php, and possibly (7) Event_for_month_per_day.php.

    Source:Drago84
    Published:16 Aug 2006
    5.1
    Medium

    CVE-2006-4158

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Drago84
    Published:16 Aug 2006
    6.8
    Medium

    CVE-2006-4157

    Last Modified: 18 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in Yet another Bulletin Board (YaBB) allows remote attackers to inject arbitrary web script or HTML via the categories parameter.

    Source:O.U.T.L.A.W
    Published:16 Aug 2006
    7.5
    High

    CVE-2006-4156

    Last Modified: 18 Sept 2013

    PHP remote file inclusion vulnerability in big.php in pearlabs mafia moblog 6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the pathtotemplate parameter. NOTE: a third party claims that the researcher is incorrect, because template.php defines pathtotemplate before big.php uses pathtotemplate. CVE has not verified either claim, but during August 2006, the original researcher made several significant errors regarding this bug type

    Source:sh3ll
    Published:16 Aug 2006
    2.6
    Low

    CVE-2006-4144

    Last Modified: 24 Sept 2013

    Integer overflow in the ReadSGIImage function in sgi.c in ImageMagick before 6.2.9 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via large (1) bytes_per_pixel, (2) columns, and (3) rows values, which trigger a heap-based buffer overflow.

    Source:Damian Put
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4142

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in extra/online.php in Virtual War (VWar) 1.5.0 R14 and earlier allows remote attackers to execute arbitrary SQL commands via the n parameter.

    Source:brOmstar
    Published:14 Aug 2006
    5
    Medium

    CVE-2006-4140

    Last Modified: 18 Sept 2013

    Directory traversal vulnerability in IPCheck Server Monitor before 5.3.3.639/640 allows remote attackers to read arbitrary files via modified .. (dot dot) sequences in the URL, including (1) "..%2f" (encoded "/" slash), "..../" (multiple dot), and "..%255c../" (double-encoded "\" backslash).

    Source:Tassi Raeburn
    Published:14 Aug 2006
    7.6
    High

    CVE-2006-4138

    Last Modified: 24 Sept 2013

    Multiple unspecified vulnerabilities in Microsoft Windows Help File viewer (winhlp32.exe) allow user-assisted attackers to execute arbitrary code via crafted HLP files.

    Source:Benjamin Tobias Franz
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4131

    Last Modified: 24 Sept 2013

    Multiple buffer overflows in ArcSoft MMS Composer 1.5.5.6, and possibly earlier, and 2.0.0.13, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted MMS (Multimedia Messaging Service) messages that trigger the overflows in the (1) M-Notification.ind, (2) M-Retrieve.conf (Header and Body), or (3) SMIL parsers.

    Source:Collin R. Mulliner
    Published:14 Aug 2006
    6.8
    Medium

    CVE-2006-4130

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin.remository.php in the Remository Component (com_remository) 3.25 and earlier for Mambo and Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:camino
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4129

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the component_dir parameter.

    Source:Mehmet Ince
    Published:14 Aug 2006
    5
    Medium

    CVE-2006-4126

    Last Modified: 24 Sept 2013

    The dc_chat function in cmd.dc.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to cause a denial of service (application crash) by sending a client message before providing the nickname, which triggers a null pointer dereference.

    Source:Luigi Auriemma
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4125

    Last Modified: 24 Sept 2013

    Stack-based buffer overflow in main.c in DConnect Daemon 0.7.0 and earlier allows remote attackers to execute arbitrary code via a large nickname, which is not properly handled by the listen_thread_udp function.

    Source:Luigi Auriemma
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4123

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in boitenews4/index.php in Boite de News 4.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the url_index parameter.

    Source:the master
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4122

    Last Modified: 18 Sept 2013

    Simple one-file guestbook 1.0 and earlier allows remote attackers to bypass authentication and delete guestbook entries via a modified id parameter to guestbook.php.

    Source:omnipresent
    Published:14 Aug 2006
    5.1
    Medium

    CVE-2006-4121

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:Drago84
    Published:14 Aug 2006
    5.1
    Medium

    CVE-2006-4115

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in common.inc.php in PgMarket 2.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CFG[libdir] parameter.

    Source:Mehmet Ince
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4114

    Last Modified: 1 Sept 2016

    SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the idsite parameter.

    Source:simo64
    Published:14 Aug 2006
    5.1
    Medium

    CVE-2006-4113

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allows remote attackers to execute arbitrary PHP code via the REP_INC parameter.

    Source:Drago84
    Published:14 Aug 2006
    4.3
    Medium

    CVE-2006-4110

    Last Modified: 18 Sept 2013

    Apache 2.2.2, when running on Windows, allows remote attackers to read source code of CGI programs via a request that contains uppercase (or alternate case) characters that bypass the case-sensitive ScriptAlias directive, but allow access to the file on case-insensitive file systems.

    Source:Susam Pal
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4103

    Last Modified: 1 Dec 2016

    PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_newsportal parameter.

    Source:Drago84
    Published:14 Aug 2006
    7.5
    High

    CVE-2006-4102

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the conf[classpath] parameter.

    Source:SirDarckCat
    Published:14 Aug 2006
    5
    Medium

    CVE-2006-4089

    Last Modified: 24 Sept 2013

    Multiple buffer overflows in Andy Lo-A-Foe AlsaPlayer 0.99.76 and earlier allow remote attackers to cause a denial of service (application crash), or have other unknown impact, via (1) a long Location field sent by a web server, which triggers an overflow in the reconnect function in reader/http/http.c; (2) a long URL sent by a web server when AlsaPlayer is seeking a media file for the playlist, which triggers overflows in new_list_item and CbUpdated in interface/gtk/PlaylistWindow.cpp; and (3) a long response sent by a CDDB server, which triggers an overflow in cddb_lookup in input/ccda/cdda_engine.c.

    Source:Luigi Auriemma
    Published:11 Aug 2006
    7.5
    High

    CVE-2006-4085

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to pagenavigation.php, a different vector than CVE-2006-4055. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Philipp Niedziela
    Published:11 Aug 2006
    7.5
    High

    CVE-2006-4081

    Last Modified: 18 Jan 2018

    preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote attackers to execute commands via shell metacharacters ("|" pipe symbol) in the file parameter. NOTE: the attack can be extended to arbitrary commands by the presence of CVE-2006-4000.

    Source:Greg Sinclair
    Published:11 Aug 2006
    7.5
    High

    CVE-2006-4077

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in CheckUpload.php in Vincenzo Valvano Comet WebFileManager (CWFM) 0.9.1, and possibly earlier, allows remote attackers to execute arbitrary PHP code via a URL in the Language parameter.

    Source:Philipp Niedziela
    Published:11 Aug 2006
    5.1
    Medium

    CVE-2006-4075

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INIT_PATH parameter to (1) lib/folder.class.php, (2) lib/email.inc.php, (3) lib/document.class.php or (4) lib/auth.inc.php.

    Source:Mehmet Ince
    Published:11 Aug 2006
    6.8
    Medium

    CVE-2006-4074

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and earlier for Joomla!, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:jank0
    Published:11 Aug 2006
    7.5
    High

    CVE-2006-4073

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbitrary PHP code via a URL in the base_dir parameter to (1) login.php, (2) reactivate.php, or (3) register.php.

    Source:Solpot
    Published:11 Aug 2006
    6.5
    Medium

    CVE-2006-4072

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL commands via the (1) haber_id parameter to haber_detay.asp, and allow remote authenticated users to execute arbitrary SQL commands via the (2) menu_id parameter to menu.asp.

    Source:ASIANEAGLE
    Published:11 Aug 2006
    2.6
    Low

    CVE-2006-4071

    Last Modified: 16 Apr 2026

    Sign extension vulnerability in the createBrushIndirect function in the GDI library (gdi32.dll) in Microsoft Windows XP, Server 2003, and possibly other versions, allows user-assisted attackers to cause a denial of service (application crash) via a crafted WMF file.

    Source:cyanid-E
    Published:10 Aug 2006
    5
    Medium

    CVE-2006-4068

    Last Modified: 17 Oct 2017

    The pswd.js script relies on the client to calculate whether a username and password match hard-coded hashed values for a server, and uses a hashing scheme that creates a large number of collisions, which makes it easier for remote attackers to conduct offline brute force attacks. NOTE: this script might also allow attackers to generate the server-side "secret" URL without determining the original password, but this possibility was not discussed by the original researcher.

    Source:Gianstefano Monni
    Published:10 Aug 2006
    5.1
    Medium

    CVE-2006-4065

    Last Modified: 1 Sept 2016

    Multiple PHP remote file inclusion vulnerabilities in Dmitry Sheiko SAPID Gallery 1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_calendar.inc.php or the (2) GLOBALS[root_path] parameter to (b) usr/extensions/get_tree.inc.php.

    Source:Kacper
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4064

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it was later reported reported that 2.0 is also affected.

    Source:ASIANEAGLE
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4063

    Last Modified: 27 Oct 2016

    Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter to (a) usr/extensions/get_blog_infochannel.inc.php, (b) usr/extensions/get_blog_meta_info.inc.php, or (c) usr/extensions/get_infochannel.inc.php; or the (2) GLOBALS[root_path] parameter to (d) usr/extensions/get_tree.inc.php.

    Source:Kacper
    Published:10 Aug 2006
    5.1
    Medium

    CVE-2006-4062

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[root_path] parameter.

    Source:Kacper
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4061

    Last Modified: 18 Sept 2013

    PHP remote file inclusion vulnerability in index.php in Thomas Pequet phpPrintAnalyzer 1.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep_par_rapport_racine parameter. NOTE: this issue has been disputed by third party researchers, stating that the rep_par_rapport_racine variable is initialized before use

    Source:sh3ll
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4060

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_dir parameter.

    Source:Mehmet Ince
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4059

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) newsscript_lyt.php, (2) newsticker/newsscript_get.php, (3) inc/output/news_theme1.php, (4) inc/output/news_theme2.php, or (5) inc/output/news_theme3.php.

    Source:Philipp Niedziela
    Published:10 Aug 2006