7.5
    High

    CVE-2006-3142

    Last Modified: 3 Sept 2013

    SQL injection vulnerability in forum.php in VBZooM 1.11 allows remote attackers to execute arbitrary SQL commands via the MainID parameter.

    Source:CrAsh_oVeR_rIdE
    Published:22 Jun 2006
    7.5
    High

    CVE-2006-3124

    Last Modified: 9 Sept 2016

    Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of service and possibly execute arbitrary code via crafted HTTP headers.

    Source:Expanders
    Published:26 Aug 2006
    5
    Medium

    CVE-2006-3121

    Last Modified: 19 Sept 2013

    The peel_netstring function in cl_netstring.c in the heartbeat subsystem in High-Availability Linux before 1.2.5, and 2.0 before 2.0.7, allows remote attackers to cause a denial of service (crash) via the length parameter in a heartbeat message.

    Source:Yan Rong Ge
    Published:17 Aug 2006
    4.3
    Medium

    CVE-2006-3109

    Last Modified: 22 Jun 2017

    Cross-site scripting (XSS) vulnerability in Cisco CallManager 3.3 before 3.3(5)SR3, 4.1 before 4.1(3)SR4, 4.2 before 4.2(3), and 4.3 before 4.3(1), allows remote attackers to inject arbitrary web script or HTML via the (1) pattern parameter in ccmadmin/phonelist.asp and (2) arbitrary parameters in ccmuser/logon.asp, aka bugid CSCsb68657.

    Source:Jake Reynolds
    Published:21 Jun 2006
    5
    Medium

    CVE-2006-3105

    Last Modified: 16 Aug 2016

    CRLF injection vulnerability in Bitweaver 1.3 allows remote attackers to conduct HTTP response splitting attacks by via CRLF sequences in multiple unspecified parameters that are injected into HTTP headers, as demonstrated by the BWSESSION parameter in index.php.

    Source:rgod
    Published:21 Jun 2006
    5
    Medium

    CVE-2006-3104

    Last Modified: 16 Aug 2016

    users/index.php in Bitweaver 1.3 allows remote attackers to obtain sensitive information via an invalid sort_mode parameter, which reveals the installation path and database information in the resultant error message.

    Source:rgod
    Published:21 Jun 2006
    4.3
    Medium

    CVE-2006-3103

    Last Modified: 16 Aug 2016

    Cross-site scripting (XSS) vulnerability in Bitweaver 1.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error parameter in users/login.php and the (2) feedback parameter in articles/index.php.

    Source:rgod
    Published:21 Jun 2006
    5.1
    Medium

    CVE-2006-3102

    Last Modified: 16 Aug 2016

    Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remote attackers to execute arbitrary PHP code by uploading arbitrary files with double extensions, which are stored for a small period of time under the webroot in the temp/articles directory.

    Source:rgod
    Published:21 Jun 2006
    4.3
    Medium

    CVE-2006-3101

    Last Modified: 3 Sept 2013

    Cross-site scripting (XSS) vulnerability in LogonProxy.cgi in Cisco Secure ACS for UNIX 2.3 allows remote attackers to inject arbitrary web script or HTML via the (1) error, (2) SSL, and (3) Ok parameters.

    Source:Thomas Liam Romanis
    Published:21 Jun 2006
    9.3
    Critical

    CVE-2006-3086

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the HrShellOpenWithMonikerDisplayName function in Microsoft Hyperlink Object Library (hlink.dll) allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long hyperlink, as demonstrated using an Excel worksheet with a long link in Unicode, aka "Hyperlink COM Object Buffer Overflow Vulnerability." NOTE: this is a different issue than CVE-2006-3059.

    Source:kingcope
    Published:19 Jun 2006
    5
    Medium

    CVE-2006-3082

    Last Modified: 4 Sept 2013

    parse-packet.c in GnuPG (gpg) 1.4.3 and 1.9.20, and earlier versions, allows remote attackers to cause a denial of service (gpg crash) and possibly overwrite memory via a message packet with a large length (long user ID string), which could lead to an integer overflow, as demonstrated using the --no-armor option.

    Source:Evgeny Legerov
    Published:31 May 2006
    4
    Medium

    CVE-2006-3081

    Last Modified: 2 Sept 2013

    mysqld in MySQL 4.1.x before 4.1.18, 5.0.x before 5.0.19, and 5.1.x before 5.1.6 allows remote authorized users to cause a denial of service (crash) via a NULL second argument to the str_to_date function.

    Source:Kanatoko
    Published:14 Jun 2006
    6.4
    Medium

    CVE-2006-3076

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in software_upload/public_includes/pub_templates/vphptree/template.php in PhpBlueDragon CMS 2.9.1 allows remote attackers to execute arbitrary PHP code via a URL in the vsDragonRootPath parameter.

    Source:Federico Fazzi
    Published:19 Jun 2006
    5
    Medium

    CVE-2006-3074

    Last Modified: 12 Dec 2013

    klif.sys in Kaspersky Internet Security 6.0 and 7.0, Kaspersky Anti-Virus (KAV) 6.0 and 7.0, KAV 6.0 for Windows Workstations, and KAV 6.0 for Windows Servers does not validate certain parameters to the (1) NtCreateKey, (2) NtCreateProcess, (3) NtCreateProcessEx, (4) NtCreateSection, (5) NtCreateSymbolicLinkObject, (6) NtCreateThread, (7) NtDeleteValueKey, (8) NtLoadKey2, (9) NtOpenKey, (10) NtOpenProcess, (11) NtOpenSection, and (12) NtQueryValueKey hooked system calls, which allows local users to cause a denial of service (reboot) via an invalid parameter, as demonstrated by the ClientId parameter to NtOpenProcess.

    Source:Matousec Transparent security
    Published:19 Jun 2006
    7.5
    High

    CVE-2006-3069

    Last Modified: 2 Sept 2013

    PHP remote file inclusion vulnerability in DoubleSpeak 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the config[private] parameter in multiple files, as demonstrated by (1) index.php, (2) faq.php, and (3) hardware.php. NOTE: this issue has been disputed by multiple third-party researchers, who state that config[private] is initialized in an include file before being used

    Source:R@1D3N
    Published:19 Jun 2006
    7.5
    High

    CVE-2006-3065

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in engine/shards/blog.php in blur6ex 0.3.462 allows remote attackers to execute arbitrary SQL commands via the ID parameter in a proc_reply action in the blog shard. NOTE: This is a similar vulnerability to CVE-2006-1763, but the affected code and versions are different.

    Source:rgod
    Published:19 Jun 2006
    2.6
    Low

    CVE-2006-3061

    Last Modified: 2 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in 5 Star Review allow remote attackers to inject arbitrary web script or HTML via the (1) sort parameter in index2.php, (2) item_id parameter in report.php, (3) search_term parameter (aka the "search box") in search_reviews.php, (4) the profile field in usercp/profile_edit1.php, and the (5) review field in review_form.php.

    Source:Luny
    Published:19 Jun 2006
    9.3
    Critical

    CVE-2006-3059

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in Microsoft Excel 2000 through 2004 allows remote user-assisted attackers to execute arbitrary code via unspecified vectors. NOTE: this is a different vulnerability than CVE-2006-3086.

    Source:naveed afzal
    Published:17 Jun 2006
    7.5
    High

    CVE-2006-3053

    Last Modified: 6 Aug 2013

    PHP remote file inclusion vulnerability in common.php in PHORUM 5.1.13 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the PHORUM[http_path] parameter. NOTE: this issue has been disputed by the vendor, who states "common.php is checked on the very first line of non-comment code that it is not being called directly. It has been this way in all 5.x version of Phorum." CVE analysis concurs with the vendor

    Source:ERNE
    Published:16 Jun 2006
    6.8
    Medium

    CVE-2006-3052

    Last Modified: 2 Sept 2013

    Cross-site scripting (XSS) vulnerability in Event Registration allows remote attackers to inject arbitrary web script or HTML via the (1) event_id parameter to view-event-details.php or (2) select_events parameter to event-registration.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Luny
    Published:16 Jun 2006
    5.1
    Medium

    CVE-2006-3051

    Last Modified: 2 Sept 2013

    Cross-site scripting (XSS) vulnerability in list.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to inject arbitrary script code or HTML via the page parameter.

    Source:Aesthetico
    Published:16 Jun 2006
    2.6
    Low

    CVE-2006-3050

    Last Modified: 2 Sept 2013

    Directory traversal vulnerability in detail.php in SixCMS 6.0, and other versions before 6.0.6patch2, allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing null (%00) byte in the template parameter.

    Source:Aesthetico
    Published:16 Jun 2006
    7.5
    High

    CVE-2006-3042

    Last Modified: 2 Sept 2013

    Multiple PHP remote file inclusion vulnerabilities in ISPConfig 2.2.3 allow remote attackers to execute arbitrary PHP code via a URL in the (1) go_info[isp][classes_root] parameter in (a) server.inc.php, and the (2) go_info[server][classes_root] parameter in (b) app.inc.php, (c) login.php, and (d) trylogin.php. NOTE: this issue has been disputed by the vendor, who states that the original researcher "reviewed the installation tarball that is not identical with the resulting system after installtion. The file, where the $go_info array is declared ... is created by the installer.

    Source:Federico Fazzi
    Published:15 Jun 2006
    5.8
    Medium

    CVE-2006-3036

    Last Modified: 2 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.

    Source:black-cod3
    Published:15 Jun 2006
    7.5
    High

    CVE-2006-3028

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:Kacper
    Published:15 Jun 2006
    7.5
    High

    CVE-2006-3027

    Last Modified: 20 Sept 2016

    Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) CAT_ID parameter in (a) subphotos.asp and (b) subLevel2.asp, the (2) AL_ID parameter in (c) photo.asp, and the (3) SUB_ID parameter in (d) subLevel2.asp.

    Source:ajann
    Published:15 Jun 2006
    7.5
    High

    CVE-2006-3019

    Last Modified: 14 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in phpCMS 1.2.1pl2 allow remote attackers to execute arbitrary PHP code via a URL in the PHPCMS_INCLUDEPATH parameter to files in parser/include/ including (1) class.parser_phpcms.php, (2) class.session_phpcms.php, (3) class.edit_phpcms.php, (4) class.http_indexer_phpcms.php, (5) class.cache_phpcms.php, (6) class.search_phpcms.php, (7) class.lib_indexer_universal_phpcms.php, and (8) class.layout_phpcms.php, (9) parser/plugs/counter.php, and (10) parser/parser.php. NOTE: the class.cache_phpcms.php vector was also reported to affect 1.1.7.

    Source:Federico Fazzi
    Published:15 Jun 2006
    7.1
    High

    CVE-2006-3015

    Last Modified: 1 Sept 2013

    Argument injection vulnerability in WinSCP 3.8.1 build 328 allows remote attackers to upload or download arbitrary files via encoded spaces and double-quote characters in a scp or sftp URI.

    Source:Jelmer Kuperus
    Published:14 Jun 2006
    5.1
    Medium

    CVE-2006-3014

    Last Modified: 17 Sept 2013

    Microsoft Excel allows user-assisted attackers to execute arbitrary javascript and redirect users to arbitrary sites via an Excel spreadsheet with an embedded Shockwave Flash Player ActiveX Object, which is automatically executed when the user opens the spreadsheet.

    Source:Debasis Mohanty
    Published:22 Jun 2006
    4.6
    Medium

    CVE-2006-3011

    Last Modified: 6 Jan 2017

    The error_log function in basic_functions.c in PHP before 4.4.4 and 5.x before 5.1.5 allows local users to bypass safe mode and open_basedir restrictions via a "php://" or other scheme in the third argument, which disables safe mode.

    Source:SecurityReason
    Published:26 Jun 2006
    5.8
    Medium

    CVE-2006-3009

    Last Modified: 1 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Open Business Management (OBM) 1.0.3 pl1 allow remote attackers to inject arbitrary HTML or web script via the (1) tf_lang, (2) tf_name, (3) tf_user, (4) tf_lastname, (5) tf_contact, (6) tf_datebefore, and (7) tf_dateafter parameters to files such as (a) publication/publication_index.php, (b) group/group_index.php, (c) user/user_index.php, (d) list/list_index.php, and (e) company/company_index.php.

    Source:r0t
    Published:13 Jun 2006
    4.3
    Medium

    CVE-2006-3006

    Last Modified: 2 Sept 2013

    Cross-site scripting (XSS) vulnerability in iFoto 0.20, and possibly other versions before 0.50, allows remote attackers to inject arbitrary HTML or web script via a base64-encoded file parameter.

    Source:Luny
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2998

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the qb_path parameter.

    Source:Kacper
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2996

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the dir[data] parameter.

    Source:Kacper
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2995

    Last Modified: 16 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the INCDIR parameter in (1) include/nav.php and (2) include/lang.php.

    Source:Kacper
    Published:13 Jun 2006
    4.3
    Medium

    CVE-2006-2986

    Last Modified: 1 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php.

    Source:Luny
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2982

    Last Modified: 16 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the absolutepath parameter in (1) footer.php and (2) admin/footer.php.

    Source:Kacper
    Published:13 Jun 2006
    7.5
    High

    CVE-2006-2973

    Last Modified: 1 Sept 2013

    Multiple SQL injection vulnerabilities in month.php in PHP Lite Calendar Express 2.2 allow remote attackers to execute arbitrary SQL commands via the (1) catid and (2) cid parameter. NOTE: this might be a duplicate of CVE-2005-4009.c.

    Source:CrAzY CrAcKeR
    Published:12 Jun 2006
    5
    Medium

    CVE-2006-2971

    Last Modified: 16 Aug 2016

    Integer overflow in the recv_packet function in 0verkill 0.16 allows remote attackers to cause a denial of service (daemon crash) via a UDP packet with fewer than 12 bytes, which results in a long length value to the crc32 function.

    Source:Federico Fazzi
    Published:12 Jun 2006
    7.5
    High

    CVE-2006-2962

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phormationdir parameter.

    Source:Kacper
    Published:12 Jun 2006
    7.5
    High

    CVE-2006-2961

    Last Modified: 26 Jan 2016

    Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long MKD command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Irving Aguilar
    Published:12 Jun 2006
    4.3
    Medium

    CVE-2006-2955

    Last Modified: 1 Sept 2013

    Multiple cross-site scripting (XSS) vulnerabilities in KAPhotoservice 7.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) New Category (newcategory) or (2) apage parameter to (a) edtalbum.asp, or the (3) cat or (4) albumid parameter to (b) album.asp.

    Source:r0t
    Published:12 Jun 2006
    5
    Medium

    CVE-2006-2947

    Last Modified: 16 Apr 2026

    Dmx Forum 2.1a allows remote attackers to obtain username and password information via a direct request to pops/edit.php with a modified membre parameter.

    Source:DarkFig
    Published:12 Jun 2006
    5
    Medium

    CVE-2006-2946

    Last Modified: 16 Apr 2026

    Dmx Forum 2.1a stores _includes/bd.inc under the web root with insufficient access control, which allows remote attackers to obtain database username and password information.

    Source:DarkFig
    Published:12 Jun 2006
    6.8
    Medium

    CVE-2006-2929

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in contrib/forms/evaluation/C_FormEvaluation.class.php in OpenEMR 2.8.1 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[fileroot] parameter.

    Source:Kacper
    Published:9 Jun 2006
    5.1
    Medium

    CVE-2006-2928

    Last Modified: 16 Aug 2016

    Multiple PHP remote file inclusion vulnerabilities in CMS-Bandits 2.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the spaw_root parameter in (1) dialogs/img.php and (2) dialogs/td.php.

    Source:Federico Fazzi
    Published:9 Jun 2006
    7.5
    High

    CVE-2006-2926

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a long URL HTTP request.

    Source:Metasploit
    Published:9 Jun 2006
    5.1
    Medium

    CVE-2006-2922

    Last Modified: 31 Aug 2013

    Multiple PHP remote file inclusion vulnerabilities in MiraksGalerie 2.62 allow remote attackers to execute arbitrary PHP code via a URL in the (1) g_pcltar_lib_dir parameter in (a) pcltar.lib.php when register_globals is enabled, and (2) listconfigfile[] parameter in (b) galsecurity.lib.php and (c) galimage.lib.php.

    Source:Federico Fazzi
    Published:9 Jun 2006
    5.1
    Medium

    CVE-2006-2914

    Last Modified: 25 Nov 2016

    PHP remote file inclusion vulnerability in DeluxeBB 1.06 allows remote attackers to execute arbitrary code via a URL in the templatefolder parameter to (1) postreply.php, (2) posting.php, (3) and pm/newpm.php in the deluxe/ directory, and (4) postreply.php, (5) posting.php, and (6) pm/newpm.php in the default/ directory.

    Source:Andreas Sandblad
    Published:23 Jun 2006
    7.5
    High

    CVE-2006-2909

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the info tip shell extension (zipinfo.dll) in PicoZip 4.01 allows remote attackers to execute arbitrary code via a long filename in an (1) ACE, (2) RAR, or (3) ZIP archive, which is triggered when the user moves the mouse over the archive.

    Source:c0rrupt
    Published:16 Jun 2006