7.5
    High

    CVE-2006-3314

    Last Modified: 3 Sept 2013

    PHP remote file inclusion vulnerability in page.php in an unspecified RahnemaCo.com product, possibly eShop, allows remote attackers to execute arbitrary PHP code via a URL in the pageid parameter.

    Source:CrAzY.CrAcKeR
    Published:29 Jun 2006
    7.5
    High

    CVE-2006-3309

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in SPT--ForumTopics.php in Scout Portal Toolkit (SPT) 1.4.0 and earlier allows remote attackers to execute arbitrary SQL commands via the forumid parameter.

    Source:simo64
    Published:29 Jun 2006
    7.5
    High

    CVE-2006-3304

    Last Modified: 25 Nov 2016

    SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL commands via the xmsn parameter.

    Source:Hessam-x
    Published:29 Jun 2006
    7.5
    High

    CVE-2006-3300

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in sms_config/gateway.php in PhpMySms 2.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the ROOT_PATH parameter.

    Source:Persian-Defacer
    Published:29 Jun 2006
    2.6
    Low

    CVE-2006-3299

    Last Modified: 6 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in Usenet Script 0.5 allows remote attackers to inject arbitrary web script or HTML via the group parameter.

    Source:Luny
    Published:29 Jun 2006
    5
    Medium

    CVE-2006-3298

    Last Modified: 5 Sept 2013

    Yahoo! Messenger 7.5.0.814 and 7.0.438 allows remote attackers to cause a denial of service (crash) via messages that contain non-ASCII characters, which triggers the crash in jscript.dll.

    Source:Ivan Ivan
    Published:29 Jun 2006
    7.5
    High

    CVE-2006-3296

    Last Modified: 6 Sept 2013

    SQL injection vulnerability in view.php in Open Guestbook 0.5 allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Source:simo64
    Published:29 Jun 2006
    4.3
    Medium

    CVE-2006-3295

    Last Modified: 6 Sept 2013

    Cross-site scripting (XSS) vulnerability in header.php in Open Guestbook 0.5 allows remote attackers to inject arbitrary web script or HTML via the title parameter.

    Source:simo64
    Published:29 Jun 2006
    5.1
    Medium

    CVE-2006-3294

    Last Modified: 31 Oct 2016

    PHP remote file inclusion vulnerability in mod_cbsms_messages.php in CBSMS Mambo Module 1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.

    Source:Kw3[R]Ln
    Published:29 Jun 2006
    7.5
    High

    CVE-2006-3292

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Search gadget in Jaws 0.6.2 allows remote attackers to execute arbitrary SQL commands via queries with the "LIKE" keyword in the searchdata parameter (search field).

    Source:rgod
    Published:28 Jun 2006
    5.1
    Medium

    CVE-2006-3281

    Last Modified: 18 Sept 2013

    Microsoft Internet Explorer 6.0 does not properly handle Drag and Drop events, which allows remote user-assisted attackers to execute arbitrary code via a link to an SMB file share with a filename that contains encoded ..\ (%2e%2e%5c) sequences and whose extension contains the CLSID Key identifier for HTML Applications (HTA), aka "Folder GUID Code Execution Vulnerability." NOTE: directory traversal sequences were used in the original exploit, although their role is not clear.

    Source:Plebo Aesdi Nael
    Published:28 Jun 2006
    7.5
    High

    CVE-2006-3280

    Last Modified: 6 Sept 2013

    Cross-domain vulnerability in Microsoft Internet Explorer 6.0 allows remote attackers to access restricted information from other domains via an object tag with a data parameter that references a link on the attacker's originating site that specifies a Location HTTP header that references the target site, which then makes that content available through the outerHTML attribute of the object, aka "Redirect Cross-Domain Information Disclosure Vulnerability."

    Source:Plebo Aesdi Nael
    Published:28 Jun 2006
    5
    Medium

    CVE-2006-3277

    Last Modified: 5 Sept 2013

    The SMTP service of MailEnable Standard 1.92 and earlier, Professional 2.0 and earlier, and Enterprise 2.0 and earlier before the MESMTPC hotfix, allows remote attackers to cause a denial of service (application crash) via a HELO command with a null byte in the argument, possibly triggering a length inconsistency or a missing argument.

    Source:db0
    Published:28 Jun 2006
    7.5
    High

    CVE-2006-3271

    Last Modified: 24 Apr 2026

    Multiple SQL injection vulnerabilities in Softbiz Dating 1.0 allow remote attackers to execute SQL commands via the (1) country and (2) sort_by parameters in (a) search_results.php; (3) browse parameter in (b) featured_photos.php; (4) cid parameter in (c) products.php, (d) index.php, and (e) news_desc.php.

    Source:41.w4r10r
    Published:28 Jun 2006
    5.1
    Medium

    CVE-2006-3269

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execute arbitrary PHP code via the phpbb_root_path parameter.

    Source:Kw3[R]Ln
    Published:28 Jun 2006
    5.1
    Medium

    CVE-2006-3266

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Bee-hive Lite 1.2 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) header parameter to (a) conad/include/rootGui.inc.php and (b) include/rootGui.inc.php; (2) mysqlCall parameter to (c) conad/changeEmail.inc.php, (d) conad/changeUserDetails.inc.php, (e) conad/checkPasswd.inc.php, (f) conad/login.inc.php and (g) conad/logout.inc.php; (3) mysqlcall parameter to (h) include/listall.inc.php; (4) prefix parameter to (i) show/index.php; and (5) config parameter to (j) conad/include/mysqlCall.inc.php.

    Source:Kw3[R]Ln
    Published:27 Jun 2006
    7.5
    High

    CVE-2006-3262

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the Weblinks module (weblinks.php) in Mambo 4.6rc1 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.

    Source:rgod
    Published:27 Jun 2006
    4.3
    Medium

    CVE-2006-3259

    Last Modified: 4 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in e107 0.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) ep parameter to search.php and the (2) subject parameter in comment.php (aka the Subject field when posting a comment).

    Source:securityconnection
    Published:27 Jun 2006
    7.5
    High

    CVE-2006-3256

    Last Modified: 5 Sept 2013

    SQL injection vulnerability in report.php in Woltlab Burning Board (WBB) 2.3.1 allows remote attackers to execute arbitrary SQL commands via the postid parameter.

    Source:CrAzY CrAcKeR
    Published:27 Jun 2006
    7.5
    High

    CVE-2006-3255

    Last Modified: 5 Sept 2013

    SQL injection vulnerability in showmods.php in Woltlab Burning Board (WBB) 1.2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

    Source:CrAzY CrAcKeR
    Published:27 Jun 2006
    7.5
    High

    CVE-2006-3254

    Last Modified: 5 Sept 2013

    SQL injection vulnerability in newthread.php in Woltlab Burning Board (WBB) 2.0 RC2 allows remote attackers to execute arbitrary SQL commands via the boardid parameter.

    Source:CrAzY CrAcKeR
    Published:27 Jun 2006
    2.6
    Low

    CVE-2006-3253

    Last Modified: 4 Sept 2013

    Cross-site scripting (XSS) vulnerability in member.php in vBulletin 3.5.x allows remote attackers to inject arbitrary web script or HTML via the u parameter. NOTE: the vendor has disputed this report, stating that they have been unable to replicate the issue and that "the userid parameter is run through our filtering system as an unsigned integer.

    Source:CrAzY.CrAcKeR
    Published:27 Jun 2006
    7.5
    High

    CVE-2006-3252

    Last Modified: 9 Mar 2011

    Buffer overflow in the Online Registration Facility for Algorithmic Research PrivateWire VPN software up to 3.7 allows remote attackers to execute arbitrary code via a long GET request.

    Source:Metasploit
    Published:27 Jun 2006
    2.6
    Low

    CVE-2006-3245

    Last Modified: 6 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters.

    Source:r0t
    Published:27 Jun 2006
    9.3
    Critical

    CVE-2006-3228

    Last Modified: 16 Aug 2016

    Buffer overflow in in_midi.dll for WinAmp 2.90 up to 5.23, including 5.21, allows remote attackers to execute arbitrary code via a crafted .mid (MIDI) file.

    Source:BassReFLeX
    Published:26 Jun 2006
    7.5
    High

    CVE-2006-3221

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary SQL commands via double-encoded values in the user parameter in a userinfo subaction.

    Source:RusH
    Published:24 Jun 2006
    7.5
    High

    CVE-2006-3213

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in WeBBoA Hosting 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter to an unspecified script, possibly host/yeni_host.asp.

    Source:EntriKa
    Published:24 Jun 2006
    5.1
    Medium

    CVE-2006-3210

    Last Modified: 16 Apr 2026

    Ralf Image Gallery (RIG) 0.7.4 and other versions before 1.0, when register_globals is enabled, allows remote attackers to conduct PHP remote file inclusion and directory traversal attacks via URLs or ".." sequences in the (1) dir_abs_src parameter in (a) check_entry.php, (b) admin_album.php, (c) admin_image.php, and (d) admin_util.php; and the (2) dir_abs_admin_src parameter in admin_album.php and admin_image.php. NOTE: this issue can be leveraged to conduct cross-site scripting (XSS) attacks.

    Source:Aesthetico
    Published:24 Jun 2006
    5
    Medium

    CVE-2006-3199

    Last Modified: 16 Aug 2016

    Opera 9 allows remote attackers to cause a denial of service (crash) via an A tag with an href attribute with a URL containing a long hostname, which triggers an out-of-bounds operation.

    Source:N9
    Published:23 Jun 2006
    4.3
    Medium

    CVE-2006-3195

    Last Modified: 4 Sept 2013

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the template parameter.

    Source:simo64
    Published:23 Jun 2006
    6.4
    Medium

    CVE-2006-3194

    Last Modified: 4 Sept 2013

    Directory traversal vulnerability in index.php in singapore 0.10.0 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the (1) gallery and (2) template parameter.

    Source:simo64
    Published:23 Jun 2006
    5.1
    Medium

    CVE-2006-3193

    Last Modified: 16 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) includes/content/contact_content.php; multiple files in adminpanel/includes/add_forms/ including (2) addbioform.php, (3) addfliersform.php, (4) addgenmerchform.php, (5) addinterviewsform.php, (6) addlinksform.php, (7) addlyricsform.php, (8) addmembioform.php, (9) addmerchform.php, (10) addmerchpicform.php, (11) addnewsform.php, (12) addphotosform.php, (13) addreleaseform.php, (14) addreleasepicform.php, (15) addrelmerchform.php, (16) addreviewsform.php, (17) addshowsform.php, (18) addwearmerchform.php; (19) adminpanel/includes/mailinglist/disphtmltbl.php, and (20) adminpanel/includes/mailinglist/dispxls.php.

    Source:Kw3[R]Ln
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3192

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via a URL in the (1) ipath parameter in common.php and (2) unspecified vectors in ad.php.

    Source:Basti
    Published:23 Jun 2006
    4.3
    Medium

    CVE-2006-3191

    Last Modified: 3 Sept 2013

    Cross-site scripting (XSS) vulnerability in comment.php in MPCS 0.2 allows remote attackers to inject arbitrary web script or HTML via the pageid parameter.

    Source:Luny
    Published:23 Jun 2006
    5.8
    Medium

    CVE-2006-3189

    Last Modified: 3 Sept 2013

    Cross-site scripting (XSS) vulnerability in administration/tblcontent/login1.php in HotPlug CMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter.

    Source:Federico Fazzi
    Published:23 Jun 2006
    4.3
    Medium

    CVE-2006-3186

    Last Modified: 28 Nov 2016

    Multiple cross-site scripting (XSS) vulnerabilities in CMS Faethon 1.3.2 allow remote attackers to inject arbitrary web script or HTML via the mainpath parameter to (1) data/footer.php and (2) admin/header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:K-159
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3185

    Last Modified: 3 Sept 2013

    PHP remote file inclusion vulnerability in data/header.php in CMS Faethon 1.3.2 allows remote attackers to execute arbitrary PHP code via a URL in the mainpath parameter.

    Source:M.Hasran Addahroni
    Published:23 Jun 2006
    4
    Medium

    CVE-2006-3184

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to execute arbitrary ASP code via the strAsgSknPageBgColour parameter to settings_skin.asp, which is stored in inc_skin_file.asp.

    Source:Hamid Ebadi
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3177

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the destination parameter.

    Source:Kacper
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3176

    Last Modified: 26 Sept 2016

    SQL injection vulnerability in xarancms_haupt.php in xarancms 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:ajann
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3175

    Last Modified: 3 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in mcGuestbook 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) admin.php, (2) ecrire.php, and (3) lire.php. NOTE: it was later reported that the ecrire.php vector also affects 1.2. NOTE: this issue might be limited to a race condition during installation or an improper installation, since a completed installation creates an include file that prevents external control of the $lang variable.

    Source:SwEET-DeViL
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3173

    Last Modified: 2 Jan 2014

    Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) path[cb] parameter to (a) libraries/comment/postComment.php and (b) modules/poll/poll.php, (2) rel parameter to (c) modules/archive/overview.inc.php, and the (3) actualModuleDir parameter to (d) modules/forum/showThread.inc.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Mehrad Ansari Targhi
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3172

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Content*Builder 0.7.5 allow remote attackers to execute arbitrary PHP code via a URL with a trailing slash (/) character in the (1) lang_path parameter to (a) cms/plugins/col_man/column.inc.php, (b) cms/plugins/poll/poll.inc.php, (c) cms/plugins/user_managment/usrPortrait.inc.php, (d) cms/plugins/user_managment/user.inc.php, (e) cms/plugins/media_manager/media.inc.php, (f) cms/plugins/events/permanent.eventMonth.inc.php, (g) cms/plugins/events/events.inc.php, and (h) cms/plugins/newsletter2/newsletter.inc.php; (2) path[cb] parameter to (i) modules/guestbook/guestbook.inc.php, (j) modules/shoutbox/shoutBox.php, and (k) modules/sitemap/sitemap.inc.php; and the (3) rel parameter to (l) modules/download/overview.inc.php, (m) modules/download/detailView.inc.php, (n) modules/article/fullarticle.inc.php, (o) modules/article/comments.inc.php, (p) modules/article2/overview.inc.php, (q) modules/article2/fullarticle.inc.php, (r) modules/article2/comments.inc.php, (s) modules/headline/headlineBox.php, and (t) modules/headline/showHeadline.inc.php.

    Source:Federico Fazzi
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-3162

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter.

    Source:Archit3ct
    Published:22 Jun 2006
    7.5
    High

    CVE-2006-3161

    Last Modified: 4 Sept 2013

    SQL injection vulnerability in misc.php in SaphpLesson 1.1 and earlier allows remote attackers to execute arbitrary SQL commands via the action parameter.

    Source:CrAzY CrAcKeR
    Published:22 Jun 2006
    7.5
    High

    CVE-2006-3158

    Last Modified: 3 Sept 2013

    index.php in Eduha Meeting does not properly restrict file extensions before permitting a file upload, which allows remote attackers to bypass security checks and upload or execute arbitrary php code via the add action.

    Source:Liz0ziM
    Published:22 Jun 2006
    4.3
    Medium

    CVE-2006-3151

    Last Modified: 31 Mar 2014

    Cross-site scripting (XSS) vulnerability in index.php in AssoCIateD (aka ACID) 1.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the menu parameter.

    Source:CWH Underground
    Published:22 Jun 2006
    6.5
    Medium

    CVE-2006-3147

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Hosting Controller before 6.1 (aka Hotfix 3.2) allows remote authenticated attackers to gain host admin privileges, list all resellers, or change resellers' passwords via unspecified vectors. NOTE: due to the lack of precise details, it is not clear whether this is related to a previously disclosed issue such as CVE-2005-1788.

    Source:Soroush Dalili
    Published:22 Jun 2006
    7.5
    High

    CVE-2006-3144

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5 (aka 0.3.5) and earlier allows remote attackers to execute arbitrary PHP code via a URL in the microcms_path parameter. NOTE: it was later reported that this can also be leveraged to include and execute arbitrary local files via .. (dot dot) sequences.

    Source:CeNGiZ-HaN
    Published:22 Jun 2006
    4
    Medium

    CVE-2006-3143

    Last Modified: 5 Sept 2013

    Cross-site scripting (XSS) vulnerability in icue_login.asp in Maximus SchoolMAX 4.0.1 and earlier iCue and iParent applications allows remote attackers to inject arbitrary web script or HTML via the error_msg parameter.

    Source:Charles Hooper
    Published:22 Jun 2006