7.5
    High

    CVE-2006-3964

    Last Modified: 15 Sept 2013

    PHP remote file inclusion vulnerability in members.php in Banex PHP MySQL Banner Exchange 2.21 allows remote attackers to execute arbitrary PHP code via a URL in the cfg_root parameter.

    Source:SirDarckCat
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3963

    Last Modified: 15 Sept 2013

    Multiple SQL injection vulnerabilities in Banex PHP MySQL Banner Exchange 2.21 allow remote attackers to execute arbitrary SQL commands via the (1) site_name parameter to (a) signup.php, and the (2) id, (3) deleteuserbanner, (4) viewmem, (5) viewmemunb, (6) viewunmem,or (7) deleteuser parameters to (b) admin.php.

    Source:SirDarckCat
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3962

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in administrator/components/com_bayesiannaivefilter/lang.php in the bayesiannaivefilter component (com_bayesiannaivefilter) 1.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Pablin77
    Published:1 Aug 2006
    6.8
    Medium

    CVE-2006-3961

    Last Modified: 10 Mar 2011

    Buffer overflow in McSubMgr ActiveX control (mcsubmgr.dll) in McAfee Security Center 6.0.23 for Internet Security Suite 2006, Wireless Home Network Security, Personal Firewall Plus, VirusScan, Privacy Service, SpamKiller, AntiSpyware, and QuickClean allows remote user-assisted attackers to execute arbitrary commands via long string parameters, which are later used in vsprintf.

    Source:Metasploit
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3960

    Last Modified: 15 Sept 2013

    SQL injection vulnerability in top.php in X-Scripts X-Poll, probably 2.30, allows remote attackers to execute arbitrary SQL commands via the poll parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:SirDarckCat
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3959

    Last Modified: 15 Sept 2013

    SQL injection vulnerability in protect.php in X-Scripts X-Protection 1.10, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the (1) username and (2) password parameter.

    Source:SirDarckCat
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3957

    Last Modified: 15 Sept 2013

    PHP remote file inclusion vulnerability in payment.php in BosDev BosDates allows remote attackers to execute arbitrary PHP code via a URL in the insPath parameter.

    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3955

    Last Modified: 24 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) news.php, (2) search.php, or (3) whosOnline.php.

    Source:AG-Spider
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3952

    Last Modified: 22 Nov 2017

    Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Winny Thomas
    Published:1 Aug 2006
    7.5
    High

    CVE-2006-3951

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in moodle.php in Mam-moodle alpha component (com_moodle) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:jank0
    Published:1 Aug 2006
    6.8
    Medium

    CVE-2006-3949

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in artlinks.dispnew.php in the Artlinks component (com_artlinks) for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:camino
    Published:1 Aug 2006
    4.3
    Medium

    CVE-2006-3948

    Last Modified: 15 Sept 2013

    Cross-site scripting (XSS) vulnerability in modules.php in PHP-Nuke INP allows remote attackers to inject arbitrary web script or HTML via the query parameter.

    Source:l2odon
    Published:1 Aug 2006
    6.8
    Medium

    CVE-2006-3947

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlier component for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Dr.Jr7
    Published:1 Aug 2006
    5
    Medium

    CVE-2006-3944

    Last Modified: 13 Sept 2013

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via a (1) Forms.ListBox.1 or (2) Forms.ListBox.1 object with the ListWidth property set to (a) 0x7fffffff, which triggers an integer overflow exception, or to (b) 0x7ffffffe, which triggers a null dereference.

    Source:hdm
    Published:31 Jul 2006
    2.6
    Low

    CVE-2006-3943

    Last Modified: 15 Sept 2013

    Stack-based buffer overflow in NDFXArtEffects in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) via long (1) RGBExtraColor, (2) RGBForeColor, and (3) RGBBackColor properties.

    Source:hdm
    Published:31 Jul 2006
    7.8
    High

    CVE-2006-3942

    Last Modified: 16 Apr 2026

    The server driver (srv.sys) in Microsoft Windows NT 4.0, 2000, XP, and Server 2003 allows remote attackers to cause a denial of service (system crash) via an SMB_COM_TRANSACTION SMB message that contains a string without null character termination, which leads to a NULL dereference in the ExecuteTransaction function, possibly related to an "SMB PIPE," aka the "Mailslot DOS" vulnerability. NOTE: the name "Mailslot DOS" was derived from incomplete initial research; the vulnerability is not associated with a mailslot.

    Source:cocoruder
    Published:31 Jul 2006
    7.5
    High

    CVE-2006-3940

    Last Modified: 15 Sept 2013

    Multiple SQL injection vulnerabilities in phpbb-Auction allow remote attackers to execute arbitrary SQL commands via (1) the ar parameter in auction_room.php and (2) the u parameter in auction_store.php. NOTE: the auction_rating.php vector is already covered by CVE-2005-1234. NOTE: the original disclosure states that the product name is "PHP-Auction", but this is probably an error.

    Source:l2odon
    Published:31 Jul 2006
    4.6
    Medium

    CVE-2006-3931

    Last Modified: 15 Sept 2013

    Buffer overflow in the daemon function in midirecord.cc in Tuomas Airaksinen Midirecord 2.0 allows local users to execute arbitrary code via a long command line argument (filename). NOTE: This may not be a vulnerability if Midirecord is not installed setuid.

    Source:Dedi Dwianto
    Published:31 Jul 2006
    7.5
    High

    CVE-2006-3930

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in admin.a6mambohelpdesk.php in a6mambohelpdesk Mambo Component 18RC1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_live_site parameter.

    Source:Dr.Jr7
    Published:31 Jul 2006
    4.3
    Medium

    CVE-2006-3929

    Last Modified: 5 Dec 2016

    Cross-site scripting (XSS) vulnerability in the Forms/rpSysAdmin script on the Zyxel Prestige 660H-61 ADSL Router running firmware 3.40(PT.0)b32 allows remote attackers to inject arbitrary web script or HTML via hex-encoded values in the a parameter.

    Source:jose.palanco
    Published:31 Jul 2006
    7.5
    High

    CVE-2006-3928

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in index.php in WMNews 0.2a and earlier allows remote attackers to execute arbitrary PHP code via a URL in the base_datapath parameter.

    Source:uNfz
    Published:31 Jul 2006
    4.3
    Medium

    CVE-2006-3927

    Last Modified: 14 Sept 2013

    Cross-site scripting (XSS) vulnerability in auctionsearch.php in PhpProBid 5.24 allows remote attackers to inject arbitrary web script or HTML via the advsrc parameter.

    Source:EllipSiS Security
    Published:31 Jul 2006
    7.5
    High

    CVE-2006-3926

    Last Modified: 14 Sept 2013

    Multiple SQL injection vulnerabilities in PhpProBid 5.24 allow remote attackers to execute arbitrary SQL commands via the (1) view or (2) start parameters to (a) viewfeedback.php or the (3) orderType parameter to (b) categories.php.

    Source:EllipSiS Security
    Published:31 Jul 2006
    7.5
    High

    CVE-2006-3922

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in mod_membre/inscription.php in PortailPHP 1.7 allows remote attackers to execute arbitrary PHP code via a URL in the chemin parameter.

    Source:Mehmet Ince
    Published:28 Jul 2006
    4.3
    Medium

    CVE-2006-3918

    Last Modified: 21 Sept 2013

    http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before 1.3.35, 2.0 before 2.0.58, and 2.2 before 2.2.2, does not sanitize the Expect header from an HTTP request when it is reflected back in an error message, which might allow cross-site scripting (XSS) style attacks using web client components that can send arbitrary headers in requests, as demonstrated using a Flash SWF file.

    Source:Thiago Zaninotti
    Published:8 May 2006
    7.5
    High

    CVE-2006-3917

    Last Modified: 24 Nov 2016

    PHP remote file inclusion vulnerability in inc/gabarits.php in R. Corson PHP Forge 3 beta 2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the cfg_racine parameter.

    Source:Virangar Security
    Published:28 Jul 2006
    5
    Medium

    CVE-2006-3915

    Last Modified: 13 Sept 2013

    Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by iterating over any native function, as demonstrated with the window.alert function, which triggers a null dereference.

    Source:hdm
    Published:28 Jul 2006
    2.1
    Low

    CVE-2006-3912

    Last Modified: 24 Aug 2016

    Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.

    Source:posidron
    Published:28 Jul 2006
    7.5
    High

    CVE-2006-3911

    Last Modified: 11 Nov 2016

    PHP remote file inclusion vulnerability in OSI Codes PHP Live! 3.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the css_path parameter in (1) help.php and (2) setup/header.php.

    Source:magnific
    Published:28 Jul 2006
    5
    Medium

    CVE-2006-3910

    Last Modified: 12 Sept 2013

    Internet Explorer 6 on Windows XP SP2, when Outlook is installed, allows remote attackers to cause a denial of service (crash) by calling the NewDefaultItem function of an OVCtl (OVCtl.OVCtl.1) ActiveX object, which triggers a null dereference.

    Source:hdm
    Published:28 Jul 2006
    6.8
    Medium

    CVE-2006-3909

    Last Modified: 15 Sept 2013

    Cross-site scripting (XSS) vulnerability in calendar.php in WWWthreads allows remote attackers to inject arbitrary web script or HTML via the week parameter.

    Source:l2odon
    Published:27 Jul 2006
    6.8
    Medium

    CVE-2006-3904

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in manager/index.php in Etomite CMS 0.6.1 and earlier, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:rgod
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3899

    Last Modified: 13 Sept 2013

    Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the stringToBinary function of the CEnroll.CEnroll.2 ActiveX object with a long second argument, which triggers an invalid memory access inside the SysAllocStringLen function.

    Source:hdm
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3898

    Last Modified: 13 Sept 2013

    Microsoft Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to cause a denial of service (application crash) by calling the Click method of the Internet.HHCtrl.1 ActiveX object before initializing the URL, which triggers a null dereference.

    Source:Alex F
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3897

    Last Modified: 13 Sept 2013

    Stack overflow in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (application crash) by creating an NMSA.ASFSourceMediaDescription.1 ActiveX object with a long dispValue property.

    Source:hdm
    Published:27 Jul 2006
    9.3
    Critical

    CVE-2006-3890

    Last Modified: 23 Apr 2026

    Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in certain other applications, allows remote attackers to execute arbitrary code via a long FilePattern attribute in a WZFILEVIEW object, a different vulnerability than CVE-2006-5198.

    Source:prdelka
    Published:21 Nov 2006
    7.5
    High

    CVE-2006-3886

    Last Modified: 28 Nov 2016

    SQL injection vulnerability in Shalwan MusicBox 2.3.4 and earlier allows remote attackers to execute arbitrary SQL commands via the page parameter in a viewgallery action in a request for the top-level URI. NOTE: the start parameter/search action is already covered by CVE-2006-1807, and the show parameter/top action is already covered by CVE-2006-1360.

    Source:EllipSiS Security
    Published:27 Jul 2006
    7.5
    High

    CVE-2006-3884

    Last Modified: 13 Sept 2013

    Multiple SQL injection vulnerabilities in links.php in Gonafish LinksCaffe 3.0 allow remote attackers to execute arbitrary SQL commands via the (1) offset and (2) limit parameters, (3) newdays parameter in a new action, and the (4) link_id parameter in a deadlink action. NOTE: this issue can also be used for path disclosure by a forced SQL error, or to modify PHP files using OUTFILE.

    Source:simo64
    Published:27 Jul 2006
    4.3
    Medium

    CVE-2006-3883

    Last Modified: 13 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Gonafish LinksCaffe 3.0 allow remote attackers to inject arbitrary web script or HTML via (1) the tablewidth parameter in (a) counter.php; (2) the newdays parameter in (b) links.php; and the (3) tableborder, (4) menucolor, (5) textcolor, and (6) bodycolor parameters in (c) menu.inc.php.

    Source:simo64
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3880

    Last Modified: 13 Sept 2013

    Microsoft Windows NT 4.0, Windows 2000, Windows XP, and Windows Small Business Server 2003 allow remote attackers to cause a denial of service (IP stack hang) via a continuous stream of packets on TCP port 135 that have incorrect TCP header checksums and random numbers in certain TCP header fields, as demonstrated by the Achilles Windows Attack Tool. NOTE: the researcher reports that the Microsoft Security Response Center has stated "Our investigation which has included code review, review of the TCPDump, and attempts on reproing the issue on multiple fresh installs of various Windows Operating Systems have all resulted in non confirmation.

    Source:J. Oquendo
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3879

    Last Modified: 16 Apr 2026

    Integer overflow in the loadChunk function in loaders/load_gt2.c in libmikmod in Mikmod Sound System 3.2.2 allows remote attackers to cause a denial of service via a GRAOUMF TRACKER (GT2) module file with a large (0xffffffff) comment length value in an XCOM chunk.

    Source:Luigi Auriemma
    Published:27 Jul 2006
    Low

    CVE-2006-3866

    Last Modified: 12 Sept 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-4868. Reason: This candidate is a duplicate of CVE-2006-4868. Notes: All CVE users should reference CVE-2006-4868 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:jamikazu
    Published:19 Sept 2006
    7.5
    High

    CVE-2006-3851

    Last Modified: 31 Aug 2016

    SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary SQL commands via the old_prefix parameter.

    Source:rgod
    Published:25 Jul 2006
    5.1
    Medium

    CVE-2006-3850

    Last Modified: 13 Sept 2013

    PHP remote file inclusion vulnerability in upgrader.php in Vanilla CMS 1.0.1 and earlier, when /conf/old_settings.php exists, allows remote attackers to execute arbitrary PHP code via a URL in the RootDirectory parameter. NOTE: this issue has been disputed by a third party who states that the RootDirectory parameter is initialized before being used, for version 1.0. CVE analysis concurs with the dispute, but it is unclear whether older versions are affected

    Source:MFox
    Published:25 Jul 2006
    5.1
    Medium

    CVE-2006-3847

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php, (5) newtask.php, and (6) rss.php, in MoSpray (aka com_mospray) 1.8 RC1 allows remote attackers to execute arbitrary PHP code via a URL in the basedir parameter.

    Source:Kurdish Security
    Published:25 Jul 2006
    6.8
    Medium

    CVE-2006-3846

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in extadminmenus.class.php in the MultiBanners 1.0.1 for Mambo allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Blue|Spy
    Published:25 Jul 2006
    9.3
    Critical

    CVE-2006-3845

    Last Modified: 12 Sept 2013

    Stack-based buffer overflow in lzh.fmt in WinRAR 3.00 through 3.60 beta 6 allows remote attackers to execute arbitrary code via a long filename in a LHA archive.

    Source:Ryan Smith
    Published:25 Jul 2006
    7.5
    High

    CVE-2006-3843

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in com_calendar.php in Calendar Mambo Module 1.5.7 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter.

    Source:Matdhule
    Published:25 Jul 2006
    10
    Critical

    CVE-2006-3838

    Last Modified: 10 Mar 2011

    Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in products including (a) Sidewinder, (b) iPolicy Security Manager, (c) Astaro Report Manager, (d) Fortinet FortiReporter, (e) Top Layer Network Security Analyzer, and possibly other products, allow remote attackers to execute arbitrary code via long (1) DELTAINTERVAL, (2) LOGFOLDER, (3) DELETELOGS, (4) FWASERVER, (5) SYSLOGPUBLICIP, (6) GETFWAIMPORTLOG, (7) GETFWADELTA, (8) DELETERDEPDEVICE, (9) COMPRESSRAWLOGFILE, (10) GETSYSLOGFIREWALLS, (11) ADDPOLICY, and (12) EDITPOLICY commands to the Syslog daemon (syslogserver.exe); (13) GUIADDDEVICE, (14) ADDDEVICE, and (15) DELETEDEVICE commands to the Topology server (Topology.exe); the (15) LICMGR_ADDLICENSE command to the License Manager (EnterpriseSecurityAnalyzer.exe); the (16) TRACE and (17) QUERYMONITOR commands to the Monitoring agent (Monitoring.exe); and possibly other vectors related to the Syslog daemon (syslogserver.exe).

    Source:Metasploit
    Published:27 Jul 2006
    5
    Medium

    CVE-2006-3836

    Last Modified: 13 Sept 2013

    Directory traversal vulnerability in index.php in UNIDOmedia Chameleon LE 1.203 and earlier, and possibly Chameleon PRO, allows remote attackers to read arbitrary files via the rmid parameter.

    Source:kicktd
    Published:25 Jul 2006