7.5
    High

    CVE-2006-4055

    Last Modified: 31 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter to (1) include/colorswitch.php, (2) contentimages.class.php, (3) ipfunctions.php, (4) configfunctions.php, (5) printpagedetails.php, or (6) log.class.php. NOTE: the copyright.php vector is already covered by CVE-2006-3993.

    Source:beford
    Published:10 Aug 2006
    5.1
    Medium

    CVE-2006-4053

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in templates/header.php in ME Download System 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the Vb8878b936c2bd8ae0cab parameter.

    Source:Philipp Niedziela
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4052

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter to (1) admin/index.php, (2) admin/adminindex.php, (3) admin/adminglobal.php, (4) admin/login.php, (5) admin/menu.php or (6) admin/header.php.

    Source:Matdhule
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4051

    Last Modified: 11 Nov 2016

    PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the abs_path parameter.

    Source:Matdhule
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4050

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in auto_check_renewals.php in phpAutoMembersArea (phpAMA) 3.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the installed_config_file parameter.

    Source:Philipp Niedziela
    Published:10 Aug 2006
    7.5
    High

    CVE-2006-4046

    Last Modified: 31 Aug 2016

    Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier on Linux/BSD, allow remote attackers to execute arbitrary code via (1) a large .S3M file handled by the mpLoadS3M function, (2) a crafted .IT file handled by the itplayerclass::module::load function, (3) a crafted .ULT file handled by the mpLoadULT function, or (4) a crafted .AMS file handled by the mpLoadAMS function.

    Source:Luigi Auriemma
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4045

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP code via a URL in the pfad parameter.

    Source:SHiKaA
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4044

    Last Modified: 1 Sept 2016

    PHP remote file inclusion vulnerability in Beautifier/Core.php in Brad Fears phpCodeCabinet 0.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the BEAUT_PATH parameter.

    Source:Minion
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4042

    Last Modified: 12 Dec 2016

    Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) title, (2) url, (3) excerpt, or (4) blog_name parameters.

    Source:rgod
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4040

    Last Modified: 29 Dec 2016

    PHP remote file inclusion vulnerability in myevent.php in myWebland myEvent 1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myevent_path parameter.

    Source:CeNGiZ-HaN
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4036

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/usercp_register.php in ZoneMetrics ZoneX Publishers Gold Edition 1.0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Mehmet Ince
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4034

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in include/html/config.php in ModernGigabyte ModernBill 1.6 allows remote attackers to execute arbitrary PHP code via a URL in the DIR parameter.

    Source:Solpot
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4029

    Last Modified: 13 Sept 2013

    Stack-based buffer overflow in sipd.dll in AGEphone 1.24 and 1.38.1 allows remote attackers to execute arbitrary code via a crafted UDP SIP packet.

    Source:Tan Chew Keong
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4026

    Last Modified: 27 Oct 2016

    PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a URL in the (1) root_path parameter in usr/extensions/get_infochannel.inc.php and the (2) GLOBALS["root_path"] parameter in usr/extensions/get_tree.inc.php.

    Source:Kacper
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4025

    Last Modified: 17 Sept 2013

    SQL injection vulnerability in profile.php in XennoBB 2.1.0 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) bday_day, (2) bday_month, and (3) bday_year parameters in the personal section.

    Source:Chris Boulton
    Published:9 Aug 2006
    7.5
    High

    CVE-2006-4024

    Last Modified: 18 Sept 2013

    The FESTAHES_Load function in pce/hes.c in Festalon 0.5.0 through 0.5.5 allows user-assisted attackers to cause a denial of service (crash) and possibly execute arbitrary code via a negative LoadAddr value in a HES file, which is used as an offset in a memcpy operation and leads to a buffer underflow.

    Source:Luigi Auriemma
    Published:9 Aug 2006
    4.6
    Medium

    CVE-2006-4020

    Last Modified: 9 Sept 2016

    scanf.c in PHP 5.1.4 and earlier, and 4.4.3 and earlier, allows context-dependent attackers to execute arbitrary code via a sscanf PHP function call that performs argument swapping, which increments an index past the end of an array and triggers a buffer over-read.

    Source:Andi
    Published:4 Aug 2006
    6.4
    Medium

    CVE-2006-4019

    Last Modified: 19 Jan 2018

    Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overwrite arbitrary program variables and read or write the attachments and preferences of other users.

    Source:GulfTech Security
    Published:11 Aug 2006
    7.5
    High

    CVE-2006-4018

    Last Modified: 24 Sept 2013

    Heap-based buffer overflow in the pefromupx function in libclamav/upx.c in Clam AntiVirus (ClamAV) 0.81 through 0.88.3 allows remote attackers to execute arbitrary code via a crafted UPX packed file containing sections with large rsize values.

    Source:Damian Put
    Published:8 Aug 2006
    5.1
    Medium

    CVE-2006-4012

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbitrary PHP code via a URL in the SITE_Path parameter to (1) poll/poll.php or (2) poll/view_polls.php. NOTE: the menu_dx.php vector is already covered by CVE-2005-2687.

    Source:Mehmet Ince
    Published:7 Aug 2006
    2.6
    Low

    CVE-2006-4011

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in esupport/admin/autoclose.php in Kayako eSupport 2.3.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the subd parameter.

    Source:beford
    Published:7 Aug 2006
    7.5
    High

    CVE-2006-4010

    Last Modified: 17 Sept 2013

    SQL injection vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: other vectors are covered by CVE-2006-3139.

    Source:mfoxhacker
    Published:7 Aug 2006
    4.3
    Medium

    CVE-2006-4009

    Last Modified: 17 Sept 2013

    Cross-site scripting (XSS) vulnerability in war.php in Virtual War (Vwar) 1.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:mfoxhacker
    Published:7 Aug 2006
    7.5
    High

    CVE-2006-4008

    Last Modified: 16 Sept 2013

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Faq 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the faq_path parameter.

    Source:Kurdish Security
    Published:7 Aug 2006
    7.5
    High

    CVE-2006-4007

    Last Modified: 16 Sept 2013

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Guestbook 3.5 allows remote attackers to execute arbitrary PHP code via a URL in the GB_PATH parameter.

    Source:Kurdish Security
    Published:7 Aug 2006
    5
    Medium

    CVE-2006-4006

    Last Modified: 16 Sept 2013

    The do_gameinfo function in BomberClone 0.11.6 and earlier, and possibly other functions, does not reset the packet data size, which causes the send_pkg function (packets.c) to use this data size when sending a reply, and allows remote attackers to read portions of server memory.

    Source:Luigi Auriemma
    Published:7 Aug 2006
    6.4
    Medium

    CVE-2006-4004

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the bbvbplang cookie, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by index.php.

    Source:r00t
    Published:7 Aug 2006
    4
    Medium

    CVE-2006-4000

    Last Modified: 16 Sept 2013

    Directory traversal vulnerability in cgi-bin/preview_email.cgi in Barracuda Spam Firewall (BSF) 3.3.01.001 through 3.3.03.053 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Greg Sinclair
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3998

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.

    Source:skulmatic
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3997

    Last Modified: 16 Sept 2013

    PHP remote file inclusion vulnerability in hsList.php in WoWRoster (aka World of Warcraft Roster) 1.5.x and earlier allows remote attackers to execute arbitrary PHP code via a URL in the subdir parameter.

    Source:skulmatic
    Published:5 Aug 2006
    6.5
    Medium

    CVE-2006-3996

    Last Modified: 24 Oct 2016

    SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execute arbitrary SQL commands via the (1) desc or (2) asc parameters.

    Source:rgod
    Published:5 Aug 2006
    6.8
    Medium

    CVE-2006-3995

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php, (4) install.uhp.php, (5) toolbar.uhp.html.php, (6) uhp.class.php, and (7) uninstall.uhp.php, in the UHP (User Home Pages) 0.5 component (aka com_uhp) for Mambo or Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Kurdish Security
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3994

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha and earlier allows remote attackers to execute arbitrary SQL commands via the u2uid parameter to u2u.php, which is directly accessed from $_POST and bypasses the protection scheme.

    Source:rgod
    Published:5 Aug 2006
    5.1
    Medium

    CVE-2006-3993

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows remote attackers to execute arbitrary PHP code via a URL in the tsep_config[absPath] parameter.

    Source:Philipp Niedziela
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3991

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter.

    Source:SHiKaA
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3990

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Paul M. Jones Savant2, possibly when used with the com_mtree component for Mambo and Joomla!, allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter in (1) Savant2_Plugin_stylesheet.php, (2) Savant2_Compiler_basic.php, (3) Savant2_Error_pear.php, (4) Savant2_Error_stack.php, (5) Savant2_Filter_colorizeCode.php, (6) Savant2_Filter_trimwhitespace.php, (7) Savant2_Plugin_ahref.php, (8) Savant2_Plugin_ahrefcontact.php, (9) Savant2_Plugin_ahreflisting.php, (10) Savant2_Plugin_ahreflistingimage.php, (11) Savant2_Plugin_ahrefmap.php, (12) Savant2_Plugin_ahrefownerlisting.php, (13) Savant2_Plugin_ahrefprint.php, (14) Savant2_Plugin_ahrefrating.php, (15) Savant2_Plugin_ahrefrecommend.php, (16) Savant2_Plugin_ahrefreport.php, (17) Savant2_Plugin_ahrefreview.php, (18) Savant2_Plugin_ahrefvisit.php, (19) Savant2_Plugin_checkbox.php, (20) Savant2_Plugin_cycle.php, (21) Savant2_Plugin_dateformat.php, (22) Savant2_Plugin_editor.php, (23) Savant2_Plugin_form.php, (24) Savant2_Plugin_image.php, (25) Savant2_Plugin_input.php, (26) Savant2_Plugin_javascript.php, (27) Savant2_Plugin_listalpha.php, (28) Savant2_Plugin_listingname.php, (29) Savant2_Plugin_modify.php, (30) Savant2_Plugin_mtpath.php, (31) Savant2_Plugin_options.php, (32) Savant2_Plugin_radios.php, (33) Savant2_Plugin_rating.php, or (34) Savant2_Plugin_textarea.php.

    Source:Crackers_Child
    Published:5 Aug 2006
    5.1
    Medium

    CVE-2006-3989

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the sb_include_path parameter.

    Source:Kurdish Security
    Published:5 Aug 2006
    5.1
    Medium

    CVE-2006-3988

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the news_include_path parameter.

    Source:Kurdish Security
    Published:5 Aug 2006
    5.1
    Medium

    CVE-2006-3987

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters.

    Source:SHiKaA
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3986

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the NL_PATH parameter.

    Source:SHiKaA
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3984

    Last Modified: 8 Dec 2016

    PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later versions, with phpAdsNew 2.0.5, allows remote attackers to execute arbitrary PHP code via a URL in the phpAds_path parameter.

    Source:Philipp Niedziela
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3983

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in editprofile.php in php(Reactor) 1.27pl1 allows remote attackers to execute arbitrary PHP code via a URL in the pathtohomedir parameter.

    Source:CeNGiZ-HaN
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-3982

    Last Modified: 16 Sept 2013

    PHP remote file inclusion vulnerability in quickie.php in Knusperleicht Quickie, probably 0.2, allows remote attackers to execute arbitrary PHP code via a URL in the QUICK_PATH parameter.

    Source:Kurdish Security
    Published:5 Aug 2006
    6.8
    Medium

    CVE-2006-3980

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM) 0.95r2 and earlier for Mambo 4.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:A-S-T TEAM
    Published:5 Aug 2006
    4.3
    Medium

    CVE-2006-3974

    Last Modified: 22 Nov 2016

    Cross-site scripting (XSS) vulnerability in cgi-bin/admin in 3Com OfficeConnect Secure Router with firmware 1.04-168 allows remote attackers to inject arbitrary web script or HTML via the tk parameter.

    Source:Secunia Research
    Published:11 Jun 2007
    5
    Medium

    CVE-2006-3972

    Last Modified: 15 Sept 2013

    Directory traversal vulnerability in includes/operator_chattranscript.php in Scott Weedon Ajax Chat, possibly 0.1, allows remote attackers to read arbitrary files via a .. (dot dot) in the chatid parameter.

    Source:SirDarckCat
    Published:2 Aug 2006
    7.5
    High

    CVE-2006-3970

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:vitux
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3969

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in administrator/components/com_colophon/admin.colophon.php in Colophon 1.2 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Drago84
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3967

    Last Modified: 15 Sept 2013

    PHP remote file inclusion vulnerability in component/option,com_moskool/Itemid,34/admin.moskool.php in MamboXChange Moskool 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:saudi.unix
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3966

    Last Modified: 31 Aug 2016

    PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter.

    Source:Philipp Niedziela
    Published:1 Aug 2006