7.6
    High

    CVE-2006-3660

    Last Modified: 22 Nov 2017

    Unspecified vulnerability in Microsoft PowerPoint 2003 has unknown impact and user-assisted attack vectors related to powerpnt.exe. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3656, and CVE-2006-3590, although it is possible that they are all different.

    Source:naveed afzal
    Published:17 Jul 2006
    2.6
    Low

    CVE-2006-3656

    Last Modified: 12 Sept 2013

    Unspecified vulnerability in Microsoft PowerPoint 2003 allows user-assisted attackers to cause memory corruption via a crafted PowerPoint file, which triggers the corruption when the file is closed. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3655, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.

    Source:naveed afzal
    Published:17 Jul 2006
    5.1
    Medium

    CVE-2006-3655

    Last Modified: 12 Sept 2013

    Unspecified vulnerability in mso.dll in Microsoft PowerPoint 2003 allows user-assisted attackers to execute arbitrary code via a crafted PowerPoint file. NOTE: due to the lack of available details as of 20060717, it is unclear how this is related to CVE-2006-3656, CVE-2006-3660, and CVE-2006-3590, although it is possible that they are all different.

    Source:naveed afzal
    Published:17 Jul 2006
    2.6
    Low

    CVE-2006-3653

    Last Modified: 17 Sept 2013

    wksss.exe 8.4.702.0 in Microsoft Works Spreadsheet 8.0 allows remote attackers to cause a denial of service (CPU consumption or crash) via crafted (1) Works, (2) Excel, and (3) Lotus 1-2-3 files.

    Source:Benjamin Franz
    Published:17 Jul 2006
    5.1
    Medium

    CVE-2006-3637

    Last Modified: 2 Sept 2013

    Microsoft Internet Explorer 5.01 SP4 and 6 does not properly handle various HTML layout component combinations, which allows user-assisted remote attackers to execute arbitrary code via a crafted HTML file that leads to memory corruption, aka "HTML Rendering Memory Corruption Vulnerability."

    Source:Kil13r
    Published:8 Aug 2006
    6.8
    Medium

    CVE-2006-3636

    Last Modified: 27 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Mailman before 2.1.9rc1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Moritz Naumann
    Published:4 Sept 2006
    4.3
    Medium

    CVE-2006-3624

    Last Modified: 11 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in FLV Players 8 allow remote attackers to inject arbitrary web script or HTML via the url parameter to (1) player.php or (2) popup.php.

    Source:xzerox
    Published:14 Jul 2006
    7.5
    High

    CVE-2006-3621

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to execute arbitrary SQL commands via the toid parameter.

    Source:Evampire chiristof
    Published:14 Jul 2006
    4.3
    Medium

    CVE-2006-3616

    Last Modified: 11 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file.

    Source:simo64
    Published:14 Jul 2006
    5.5
    Medium

    CVE-2006-3611

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in pm.php in Phorum 5 allows remote authenticated users to include and execute arbitrary local files via directory traversal sequences in the GLOBALS[template] parameter, as demonstrated by injecting PHP sequences into a log file, which is then included by pm.php.

    Source:rgod
    Published:14 Jul 2006
    4.6
    Medium

    CVE-2006-3608

    Last Modified: 11 Sept 2013

    The Gallery module in Simone Vellei Flatnuke 2.5.7 and earlier, when Gallery uploads are enabled, does not restrict the extensions of uploaded files that begin with a GIF header, which allows remote authenticated users to execute arbitrary PHP code via an uploaded .php file.

    Source:rgod
    Published:14 Jul 2006
    4.3
    Medium

    CVE-2006-3607

    Last Modified: 6 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Softbiz Banner Exchange Script (aka Banner Exchange Network Script) 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the city parameter in (a) insertmember.php, and (2) a PHPSESSID cookie in (b) lostpassword.php, (c) gen_confirm_mem.php, and (d) index.php.

    Source:securityconnection
    Published:14 Jul 2006
    5
    Medium

    CVE-2006-3605

    Last Modified: 11 Sept 2013

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (crash) by setting the Transition property on an uninitialized DXImageTransform.Microsoft.RevealTrans.1 ActiveX Object, which triggers a null dereference.

    Source:hdm
    Published:14 Jul 2006
    7.5
    High

    CVE-2006-3604

    Last Modified: 11 Sept 2013

    Directory traversal vulnerability in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to bypass access restrictions for (1) admin/aindex.asp or (2) admin/aindex.html via a .. (dot dot) and encoded / (%2f) sequence in the URL.

    Source:Jaime Blasco
    Published:14 Jul 2006
    5.8
    Medium

    CVE-2006-3603

    Last Modified: 11 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in FlexWATCH Network Camera 3.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the URL.

    Source:Jaime Blasco
    Published:14 Jul 2006
    5
    Medium

    CVE-2006-3602

    Last Modified: 10 Sept 2013

    Directory traversal vulnerability in jscripts/tiny_mce/tiny_mce_gzip.php in FarsiNews 3.0 BETA 1 allows remote attackers to include arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the language parameter in the advanced theme.

    Source:armin390
    Published:14 Jul 2006
    4.6
    Medium

    CVE-2006-3592

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the command line interface (CLI) in Cisco Unified CallManager (CUCM) 5.0(1) through 5.0(3a) allows local users to execute arbitrary commands with elevated privileges via unspecified vectors, involving "certain CLI commands," aka bug CSCse11005.

    Published:14 Jul 2006
    5
    Medium

    CVE-2006-3591

    Last Modified: 11 Sept 2013

    Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the URL property of a TriEditDocument.TriEditDocument object before it has been initialized, which triggers a NULL pointer dereference.

    Source:hdm
    Published:14 Jul 2006
    5.1
    Medium

    CVE-2006-3581

    Last Modified: 9 Sept 2013

    Multiple stack-based buffer overflows in Audacious AdPlug 2.0 and earlier allow remote user-assisted attackers to execute arbitrary code via large (1) DTM and (2) S3M files.

    Source:Luigi Auriemma
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3580

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in pages.asp in ASP Stats Generator before 2.1.2 allows remote attackers to execute arbitrary SQL commands via the order parameter.

    Source:Hamid Ebadi
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3577

    Last Modified: 9 Sept 2013

    SQL injection vulnerability in index.php in LifeType 1.0.5 allows remote attackers to execute arbitrary SQL commands via the Date parameter in a Default op.

    Source:Alejandro Ramos
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3572

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

    Source:rgod
    Published:13 Jul 2006
    2.6
    Low

    CVE-2006-3571

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in interna/hilfe.php in Papoo 3 RC3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) titel or (2) ausgabe parameters.

    Source:rgod
    Published:13 Jul 2006
    4.3
    Medium

    CVE-2006-3568

    Last Modified: 11 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in guestbook.php in Fantastic Guestbook 2.0.1, and possibly earlier versions, allow remote attackers to inject arbitrary web script or HTML via the (1) first_name, (2) last_name, or (3) nickname parameters.

    Source:omnipresent
    Published:13 Jul 2006
    2.6
    Low

    CVE-2006-3563

    Last Modified: 5 Sept 2013

    Cross-site scripting (XSS) vulnerability in gallery/thumb.php in Winged Gallery 1.0 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Source:Luny
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3562

    Last Modified: 7 Sept 2013

    PHP remote file inclusion vulnerabilities in plume cms 1.0.4 allow remote attackers to execute arbitrary PHP code via a URL in the _PX_config[manager_path] parameter to (1) index.php, (2) rss.php, or (3) search.php, a different set of vectors and versions than CVE-2006-2645 and CVE-2006-0725.

    Source:CrAsh_oVeR_rIdE
    Published:13 Jul 2006
    5
    Medium

    CVE-2006-3561

    Last Modified: 16 Apr 2026

    BT Voyager 2091 Wireless firmware 2.21.05.08m_A2pB018c1.d16d and earlier, and 3.01m and earlier, allow remote attackers to bypass the authentication process and gain sensitive information, such as configuration information via (1) /btvoyager_getconfig.sh, PPP credentials via (2) btvoyager_getpppcreds.sh, and decode configuration credentials via (3) btvoyager_decoder.c.

    Source:Adrian _pagvac_ Pastor
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3560

    Last Modified: 10 Sept 2013

    SQL injection vulnerability in topics.php in Blue Dojo Graffiti Forums 1.0 allows remote attackers to execute arbitrary SQL commands via the f parameter.

    Source:Paisterist
    Published:13 Jul 2006
    6.8
    Medium

    CVE-2006-3556

    Last Modified: 10 Sept 2013

    PHP remote file inclusion vulnerability in extcalendar.php in Mohamed Moujami ExtCalendar 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:13 Jul 2006
    5
    Medium

    CVE-2006-3546

    Last Modified: 7 Nov 2017

    Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via a long HTTP POST request. NOTE: this might be the same issue as CVE-2004-2463.

    Source:Xavier de Leon
    Published:13 Jul 2006
    7.5
    High

    CVE-2006-3543

    Last Modified: 8 Jan 2018

    Multiple SQL injection vulnerabilities in Invision Power Board (IPB) 1.x and 2.x allow remote attackers to execute arbitrary SQL commands via the (1) idcat and (2) code parameters in a ketqua action in index.php; the id parameter in a (3) Attach and (4) ref action in index.php; the CODE parameter in a (5) Profile, (6) Login, and (7) Help action in index.php; and the (8) member_id parameter in coins_list.php. NOTE: the developer has disputed this issue, stating that the "CODE attribute is never present in an SQL query" and the "'ketqua' [action] and file 'coin_list.php' are not standard IPB 2.x features". It is unknown whether these vectors are associated with an independent module or modification of IPB

    Source:CrAzY CrAcKeR
    Published:13 Jul 2006
    5.8
    Medium

    CVE-2006-3533

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) fg, (2) line1, (3) line2, (4) bg, (5) c1, (6) c2, (7) c3, and (8) c4 parameters in (a) includes/blogroll.php; (9) name and (10) js_name parameters in (b) includes/editor/edit_menu.php; and, even if register_globals is not enabled, the (11) h and (12) w parameters in (c) includes/photo.php.

    Source:rgod
    Published:12 Jul 2006
    5.1
    Medium

    CVE-2006-3532

    Last Modified: 16 Apr 2026

    PHP file inclusion vulnerability in includes/edit_new.php in Pivot 1.30 RC2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a FTP URL or full file path in the Paths[extensions_path] parameter.

    Source:rgod
    Published:12 Jul 2006
    7.5
    High

    CVE-2006-3531

    Last Modified: 16 Apr 2026

    includes/editor/insert_image.php in Pivot 1.30 RC2 and earlier creates the authentication credentials from parameters, which allows remote attackers to obtain privileges and upload arbitrary files via modified (1) pass and (2) session parameters, and (3) pass and (4) userlevel indices of the (a) Pivot_Vars[] or (b) Users[] array parameters.

    Source:rgod
    Published:12 Jul 2006
    6.8
    Medium

    CVE-2006-3530

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Joomla 0.3 and possibly up to 1.3.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the mosConfig_absolute_path parameter.

    Source:Matdhule
    Published:12 Jul 2006
    6.8
    Medium

    CVE-2006-3528

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Simpleboard Mambo module 1.1.0 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the sbp parameter to (1) image_upload.php and (2) file_upload.php.

    Source:h4ntu
    Published:12 Jul 2006
    7.5
    High

    CVE-2006-3524

    Last Modified: 16 Apr 2026

    Buffer overflow in SIPfoundry sipXtapi released before 20060324 allows remote attackers to execute arbitrary code via a long CSeq field value in an INVITE message.

    Source:Michael Thumann
    Published:12 Jul 2006
    7.5
    High

    CVE-2006-3520

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in skins/advanced/advanced1.php in Sabdrimer Pro 2.2.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pluginpath[0] parameter.

    Source:A.nosrati
    Published:12 Jul 2006
    7.5
    High

    CVE-2006-3518

    Last Modified: 10 Sept 2013

    SQL injection vulnerability in SayfalaAltList.asp in Webvizyon Portal 2006 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:StorMBoY
    Published:11 Jul 2006
    7.5
    High

    CVE-2006-3517

    Last Modified: 10 Sept 2013

    PHP remote file inclusion vulnerability in stats.php in RW::Download, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:StorMBoY
    Published:11 Jul 2006
    5
    Medium

    CVE-2006-3513

    Last Modified: 10 Sept 2013

    danim.dll in Microsoft Internet Explorer 6 allows remote attackers to cause a denial of service (application crash) by accessing the Data property of a DirectAnimation DAUserData object before it is initialized, which triggers a NULL pointer dereference.

    Source:hdm
    Published:11 Jul 2006
    5
    Medium

    CVE-2006-3512

    Last Modified: 10 Sept 2013

    Internet Explorer 6 on Windows XP allows remote attackers to cause a denial of service (crash) by setting the Enabled property of a DXTFilter ActiveX object to true, which triggers a null dereference.

    Source:hdm
    Published:11 Jul 2006
    5
    Medium

    CVE-2006-3511

    Last Modified: 24 May 2017

    Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service (crash) by setting the fonts property of the HtmlDlgSafeHelper object, which triggers a null dereference.

    Source:hdm
    Published:11 Jul 2006
    2.6
    Low

    CVE-2006-3510

    Last Modified: 10 Sept 2013

    The Remote Data Service Object (RDS.DataControl) in Microsoft Internet Explorer 6 on Windows 2000 allows remote attackers to cause a denial of service (crash) via a series of operations that result in an invalid length calculation when using SysAllocStringLen, then triggers a buffer over-read.

    Source:hdm
    Published:11 Jul 2006
    7.2
    High

    CVE-2006-3507

    Last Modified: 11 Oct 2013

    Multiple stack-based buffer overflows in the AirPort wireless driver on Apple Mac OS X 10.3.9 and 10.4.7 allow physically proximate attackers to execute arbitrary code by injecting crafted frames into a wireless network.

    Source:David Maynor
    Published:21 Sept 2006
    5.1
    Medium

    CVE-2006-3493

    Last Modified: 16 Apr 2026

    Buffer overflow in LsCreateLine function (mso_203) in mso.dll and mso9.dll, as used by Microsoft Word and possibly other products in Microsoft Office 2003, 2002, and 2000, allows remote user-assisted attackers to cause a denial of service (crash) via a crafted Word DOC or other Office file type. NOTE: this issue was originally reported to allow code execution, but on 20060710 Microsoft stated that code execution is not possible, and the original researcher agrees.

    Source:naveed afzal
    Published:10 Jul 2006
    7.5
    High

    CVE-2006-3491

    Last Modified: 10 Sept 2013

    Stack-based buffer overflow in Kaillera Server 0.86 and earlier allows remote attackers to execute arbitrary code via a long nickname.

    Source:Luigi Auriemma
    Published:10 Jul 2006
    2.6
    Low

    CVE-2006-3484

    Last Modified: 27 Jun 2017

    Multiple cross-site scripting (XSS) vulnerabilities in ATutor before 1.5.3 allow remote attackers to inject arbitrary web script or HTML via the (1) show_courses or (2) current_cat parameters to (a) admin/create_course.php, show_courses parameter to (b) users/create_course.php, (3) p parameter to (c) documentation/admin/, (4) forgot parameter to (d) password_reminder.php, (5) cat parameter to (e) users/browse.php, or the (6) submit parameter to admin/fix_content.php.

    Source:Security News
    Published:10 Jul 2006
    7.5
    High

    CVE-2006-3478

    Last Modified: 9 Dec 2016

    PHP remote file inclusion vulnerability in styles/default/global_header.php in MyPHP CMS 0.3 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the domain parameter.

    Source:Kw3[R]Ln
    Published:10 Jul 2006
    4.3
    Medium

    CVE-2006-3476

    Last Modified: 21 Dec 2016

    Cross-site scripting (XSS) vulnerability in comments.php in PhpWebGallery 1.5.2 and earlier, and possibly 1.6.0, allows remote attackers to inject arbitrary web script or HTML via the keyword parameter.

    Source:iss4m
    Published:10 Jul 2006