5
    Medium

    CVE-2006-3835

    Last Modified: 13 Sept 2013

    Apache Tomcat 5 before 5.5.17 allows remote attackers to list directories via a semicolon (;) preceding a filename with a mapped extension, as demonstrated by URLs ending with /;index.jsp and /;help.do.

    Source:ScanAlert Security
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3832

    Last Modified: 29 Dec 2016

    SQL injection vulnerability in index.php in Gerrit van Aaken Loudblog 0.5 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:rgod
    Published:25 Jul 2006
    4.9
    Medium

    CVE-2006-3824

    Last Modified: 27 Oct 2016

    systeminfo.c for Sun Solaris allows local users to read kernel memory via a 0 variable count argument to the sysinfo system call, which causes a -1 argument to be used by the copyout function. NOTE: this issue has been referred to as an integer overflow, but it is probably more like a signedness error or integer underflow.

    Source:prdelka
    Published:25 Jul 2006
    5.1
    Medium

    CVE-2006-3823

    Last Modified: 6 Nov 2017

    SQL injection vulnerability in index.php in GeodesicSolutions (1) GeoAuctions Premier 2.0.3 and (2) GeoClassifieds Basic 2.0.3 allows remote attackers to execute arbitrary SQL commands via the b parameter.

    Source:Esac
    Published:25 Jul 2006
    5.1
    Medium

    CVE-2006-3822

    Last Modified: 13 Sept 2013

    SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to execute arbitrary SQL commands via the d parameter.

    Source:LBDT
    Published:25 Jul 2006
    7.5
    High

    CVE-2006-3819

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in the configure script in TWiki 4.0.0 through 4.0.4 allows remote attackers to execute arbitrary Perl code via an HTTP POST request containing a parameter name starting with "TYPEOF".

    Source:Javier Olascoaga
    Published:27 Jul 2006
    2.1
    Low

    CVE-2006-3815

    Last Modified: 15 Sept 2013

    heartbeat.c in heartbeat before 2.0.6 sets insecure permissions in a shmget call for shared memory, which allows local users to cause an unspecified denial of service via unknown vectors, possibly during a short time window on startup.

    Source:anonymous
    Published:24 Jul 2006
    5.1
    Medium

    CVE-2006-3814

    Last Modified: 16 Apr 2026

    Buffer overflow in the Loader_XM::load_instrument_internal function in loader_xm.cpp for Cheese Tracker 0.9.9 and earlier allows user-assisted attackers to execute arbitrary code via a crafted file with a large amount of extra data.

    Source:Luigi Auriemma
    Published:24 Jul 2006
    5.1
    Medium

    CVE-2006-3793

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the SD_DIR parameter.

    Source:Aesthetico
    Published:21 Jul 2006
    2.1
    Low

    CVE-2006-3787

    Last Modified: 17 Sept 2013

    kpf4ss.exe in Sunbelt Kerio Personal Firewall 4.3.x before 4.3.268 does not properly hook the CreateRemoteThread API function, which allows local users to cause a denial of service (crash) and bypass protection mechanisms by calling CreateRemoteThread.

    Source:David Matousek
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3777

    Last Modified: 12 Sept 2013

    PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:r0t
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3776

    Last Modified: 12 Sept 2013

    PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:r0t
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3775

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote attackers to execute arbitrary SQL commands via the CLIENT-IP HTTP header ($_SERVER['HTTP_CLIENT_IP'] variable), as utilized by index.php.

    Source:rgod
    Published:21 Jul 2006
    6.8
    Medium

    CVE-2006-3774

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:endeneu
    Published:21 Jul 2006
    6.8
    Medium

    CVE-2006-3773

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and Mambo 4.5.3+ allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:ASIANEAGLE
    Published:21 Jul 2006
    5.1
    Medium

    CVE-2006-3772

    Last Modified: 16 Apr 2026

    PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass security restrictions and obtain administrative privileges by modifying the logincookie[user] setting in the login cookie.

    Source:FarhadKey
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3771

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) articles.php, (2) contact.php, (3) displaypage.php, (4) faq.php, (5) mainbody.php, (6) news.php, (7) registration.php, (8) whosOnline.php, (9) components/com_calendar.php, (10) components/com_forum.php, (11) components/minibb/index.php, (12) components/minibb/bb_admin.php, (13) components/minibb/bb_plugins.php, (14) modules/mod_calendar.php, (15) modules/mod_browser_prefs.php, (16) modules/mod_counter.php, (17) modules/mod_online.php, (18) modules/mod_stats.php, (19) modules/mod_weather.php, (20) themes/bizz.php, (21) themes/default.php, (22) themes/simple.php, (23) themes/original.php, (24) themes/portal.php, (25) themes/purple.php, and other unspecified files.

    Source:Matdhule
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3763

    Last Modified: 22 Dec 2016

    SQL injection vulnerability in category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:black-code
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3755

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Include/editor/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:igi
    Published:20 Jul 2006
    7.5
    High

    CVE-2006-3754

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Include/editor/rich_files/class.rich.php in FlushCMS 1.0.0-pre2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the class_path parameter.

    Source:igi
    Published:20 Jul 2006
    6.8
    Medium

    CVE-2006-3751

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_htmlarea3_xtd-c) for ImageManager 1.5 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:20 Jul 2006
    6.8
    Medium

    CVE-2006-3750

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in server.php in the Hashcash Component (com_hashcash) 1.2.1 for Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:20 Jul 2006
    6.8
    Medium

    CVE-2006-3749

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sitemap.xml.php in Sitemap component (com_sitemap) 2.0.0 for Mambo 4.5.1 CMS, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:20 Jul 2006
    6.8
    Medium

    CVE-2006-3748

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in includes/abbc/abbc.class.php in the LoudMouth Component for Mambo 4.0j, and possibly other versions including 4.1, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:h4ntu
    Published:20 Jul 2006
    7.6
    High

    CVE-2006-3747

    Last Modified: 27 Oct 2016

    Off-by-one error in the ldap scheme handling in the Rewrite module (mod_rewrite) in Apache 1.3 from 1.3.28, 2.0.46 and other versions before 2.0.59, and 2.2, when RewriteEngine is enabled, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via crafted URLs that are not properly handled using certain rewrite rules.

    Source:Jacobo Avariento
    Published:28 Jul 2006
    5
    Medium

    CVE-2006-3746

    Last Modified: 13 Sept 2013

    Integer overflow in parse_comment in GnuPG (gpg) 1.4.4 allows remote attackers to cause a denial of service (segmentation fault) via a crafted message.

    Source:Evgeny Legerov
    Published:21 Jul 2006
    7.5
    High

    CVE-2006-3736

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:h4ntu
    Published:19 Jul 2006
    5.1
    Medium

    CVE-2006-3735

    Last Modified: 24 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the m2f_root_path parameter to (1) m2f/m2f_phpbb204.php, (2) m2f/m2f_forum.php, (3) m2f/m2f_mailinglist.php or (4) m2f/m2f_cron.php.

    Source:OLiBekaS
    Published:19 Jul 2006
    7.2
    High

    CVE-2006-3734

    Last Modified: 16 Apr 2026

    Multiple unspecified vulnerabilities in the Command Line Interface (CLI) for Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allow local CS-MARS administrators to execute arbitrary commands as root.

    Source:Jon Hart
    Published:19 Jul 2006
    7.5
    High

    CVE-2006-3733

    Last Modified: 12 Sept 2013

    jmx-console/HtmlAdaptor in the jmx-console in the JBoss web application server, as shipped with Cisco Security Monitoring, Analysis and Response System (CS-MARS) before 4.2.1, allows remote attackers to gain privileges as the CS-MARS administrator and execute arbitrary Java code via an invokeOp action in the BSHDeployer jboss.scripts service name.

    Source:Jon Hart
    Published:19 Jul 2006
    8.8
    High

    CVE-2006-3730

    Last Modified: 14 Sept 2016

    Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a 0x7fffffff argument to the setSlice method on a WebViewFolderIcon ActiveX object, which leads to an invalid memory copy.

    Source:YAG KOHHA
    Published:19 Jul 2006
    2.6
    Low

    CVE-2006-3729

    Last Modified: 12 Sept 2013

    DataSourceControl in Internet Explorer 6 on Windows XP SP2 with Office installed allows remote attackers to cause a denial of service (crash) via a large negative integer argument to the getDataMemberName method of a OWC11.DataSourceControl.11 object, which leads to an integer overflow and a null dereference.

    Source:hdm
    Published:19 Jul 2006
    7.5
    High

    CVE-2006-3727

    Last Modified: 31 Aug 2016

    Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) gr_1_id, (2) gr_2_id, (3) gr_3_id, and (4) doc_id parameters in (a) index.php; the (5) uid and (6) pwd parameters in (b) php/esa.php; and possibly other vectors related to files in php/lib/ including (c) del.php, (d) download_backup.php, (e) navig.php, (f) restore.php, (g) set_12.php, (h) set_14.php, and (i) upd_doc.php.

    Source:Jacek Wlodarczyk
    Published:19 Jul 2006
    6.5
    Medium

    CVE-2006-3726

    Last Modified: 15 Nov 2017

    Buffer overflow in FileCOPA FTP Server before 1.01 released on 18th July 2006, allows remote authenticated attackers to execute arbitrary code via a long argument to the LIST command.

    Source:Metasploit
    Published:19 Jul 2006
    10
    Critical

    CVE-2006-3698

    Last Modified: 26 Sept 2016

    Multiple unspecified vulnerabilities in Oracle Database 10.1.0.5 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB01 for Change Data Capture (CDC) component and (2) DB03 for Data Pump Metadata API. NOTE: as of 20060719, Oracle has not disputed a claim by a reliable researcher that DB01 is related to multiple SQL injection vulnerabilities in SYS.DBMS_CDC_IMPDP using the (a) IMPORT_CHANGE_SET, (b) IMPORT_CHANGE_TABLE, (c) IMPORT_CHANGE_COLUMN, (d) IMPORT_SUBSCRIBER, (e) IMPORT_SUBSCRIBED_TABLE, (f) IMPORT_SUBSCRIBED_COLUMN, (g) VALIDATE_IMPORT, (h) VALIDATE_CHANGE_SET, (i) VALIDATE_CHANGE_TABLE, and (j) VALIDATE_SUBSCRIPTION procedures, and that DB03 is for SQL injection in the MAIN procedure for SYS.KUPW$WORKER.

    Source:Joxean Koret
    Published:19 Jul 2006
    2.1
    Low

    CVE-2006-3696

    Last Modified: 12 Sept 2013

    filtnt.sys in Outpost Firewall Pro before 3.51.759.6511 (462) allows local users to cause a denial of service (crash) via long arguments to mshta.exe.

    Source:Bipin Gautam
    Published:19 Jul 2006
    4.6
    Medium

    CVE-2006-3693

    Last Modified: 16 Apr 2026

    Rocks Clusters 4.1 and earlier allows local users to gain privileges via commands enclosed with escaped backticks (\`) in an argument to the (1) mount-loop (mount-loop.c) or (2) umount-loop (umount-loop.c) command, which is not filtered in a system function call.

    Source:Xavier de Leon
    Published:19 Jul 2006
    7.5
    High

    CVE-2006-3692

    Last Modified: 12 Sept 2013

    PHP remote file inclusion vulnerability in enduser/listmessenger.php in ListMessenger 0.9.3 allows remote attackers to execute arbitrary PHP code via a URL in the lm_path parameter. NOTE: the vendor has disputed this issue to SecurityTracker, stating that the $lm_path variable is set to a constant value. As of 20060726, CVE concurs with the vendor based on SecurityTracker's post-disclosure analysis

    Source:xoron
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3690

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolute_path parameter to (1) components/com_minibb.php or (2) components/minibb/index.php.

    Source:Matdhule
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3689

    Last Modified: 12 Sept 2013

    PHP remote file inclusion vulnerability in user-func.php in Codeworks Gnomedia SubberZ[Lite] allows remote attackers to execute arbitrary PHP code via a URL in the myadmindir parameter. NOTE: this issue has been disputed by a third party that claims that " the myadmindir variable is set before any GET variables are processed.

    Source:Chironex Fleckeri
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3687

    Last Modified: 12 Sept 2013

    Stack-based buffer overflow in the Universal Plug and Play (UPnP) service in D-Link DI-524, DI-604 Broadband Router, DI-624, D-Link DI-784, WBR-1310 Wireless G Router, WBR-2310 RangeBooster G Router, and EBR-2310 Ethernet Broadband Router allows remote attackers to execute arbitrary code via a long M-SEARCH request to UDP port 1900.

    Source:Barnaby Jack
    Published:18 Jul 2006
    5.1
    Medium

    CVE-2006-3685

    Last Modified: 22 Dec 2016

    PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP code via a URL in the tpath parameter to cn_config.php. NOTE: the news.php vector is already covered by CVE-2005-0859.

    Source:SHiKaA
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3683

    Last Modified: 27 Sept 2016

    PHP remote file inclusion vulnerability in poll.php in Flipper Poll 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:Mehmet Ince
    Published:18 Jul 2006
    5
    Medium

    CVE-2006-3682

    Last Modified: 15 Apr 2014

    awstats.pl in AWStats 6.5 build 1.857 and earlier allows remote attackers to obtain the installation path via the (1) year, (2) pluginmode or (3) month parameters.

    Source:r0t
    Published:18 Jul 2006
    2.6
    Low

    CVE-2006-3680

    Last Modified: 11 Sept 2013

    Cross-site scripting (XSS) vulnerability in photocycle in Photocycle 1.0 allows remote attackers to inject arbitrary web script or HTML via the phpage parameter.

    Source:Luny
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3677

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5 before 1.5.0.5 and SeaMonkey before 1.0.3 allows remote attackers to execute arbitrary code by changing certain properties of the window navigator object (window.navigator) that are accessed when Java starts up, which causes a crash that leads to code execution.

    Source:H D Moore
    Published:26 Jul 2006
    2.6
    Low

    CVE-2006-3672

    Last Modified: 11 Sept 2013

    KDE Konqueror 3.5.1 and earlier allows remote attackers to cause a denial of service (application crash) by calling the replaceChild method on a DOM object, which triggers a null dereference, as demonstrated by calling document.replaceChild with a 0 (zero) argument.

    Source:hdm
    Published:18 Jul 2006
    7.5
    High

    CVE-2006-3670

    Last Modified: 27 Apr 2011

    Stack-based buffer overflow in Winlpd 1.26 allows remote attackers to execute arbitrary code via a long string in a request to TCP port 515.

    Source:Pablo Isola
    Published:18 Jul 2006
    7.6
    High

    CVE-2006-3668

    Last Modified: 16 Apr 2026

    Heap-based buffer overflow in the it_read_envelope function in Dynamic Universal Music Bibliotheque (DUMB) 0.9.3 and earlier and current CVS as of 20060716, including libdumb, allows user-assisted attackers to execute arbitrary code via a ".it" (Impulse Tracker) file with an envelope with a large number of nodes.

    Source:Luigi Auriemma
    Published:17 Jul 2006
    7.5
    High

    CVE-2006-3662

    Last Modified: 10 Sept 2013

    SQL injection vulnerability in index.php in ATutor 1.5.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter. NOTE: this issue has been disputed by the vendor, who states "The mentioned SQL injection vulnerability is not possible." However, the relevant source code suggests that this issue may be legitimate, and the parameter is cleansed in 1.5.3.1

    Source:securityconnection
    Published:17 Jul 2006