7.5
    High

    CVE-2006-2908

    Last Modified: 16 Apr 2026

    The domecode function in inc/functions_post.php in MyBulletinBoard (MyBB) 1.1.2, and possibly other versions, allows remote attackers to execute arbitrary PHP code via the username field, which is used in a preg_replace function call with a /e (executable) modifier.

    Source:Javier Olascoaga
    Published:13 Jun 2006
    5.4
    Medium

    CVE-2006-2906

    Last Modified: 31 Aug 2013

    The LZW decoding in the gdImageCreateFromGifPtr function in the Thomas Boutell graphics draw (GD) library (aka libgd) 2.0.33 allows remote attackers to cause a denial of service (CPU consumption) via malformed GIF data that causes an infinite loop.

    Source:Xavier Roche
    Published:8 Jun 2006
    5
    Medium

    CVE-2006-2901

    Last Modified: 16 Apr 2026

    The web server for D-Link Wireless Access-Point (DWL-2100ap) firmware 2.10na and earlier allows remote attackers to obtain sensitive system information via a request to an arbitrary .cfg file, which returns configuration information including passwords.

    Source:INTRUDERS
    Published:7 Jun 2006
    6.5
    Medium

    CVE-2006-2899

    Last Modified: 31 Aug 2013

    Unspecified vulnerability in ESTsoft InternetDISK versions before 2006/04/20 allows remote authenticated users to execute arbitrary code, possibly by uploading a file with multiple extensions into the WebLink directory.

    Source:Kil13r
    Published:7 Jun 2006
    5
    Medium

    CVE-2006-2896

    Last Modified: 16 Apr 2026

    profile.php in FunkBoard CF0.71 allows remote attackers to change arbitrary passwords via a modified uid hidden form field in an Edit Profile action.

    Source:ajann
    Published:7 Jun 2006
    4
    Medium

    CVE-2006-2894

    Last Modified: 31 Aug 2013

    Mozilla Firefox 1.5.0.4, 2.0.x before 2.0.0.8, Mozilla Suite 1.7.13, Mozilla SeaMonkey 1.0.2 and other versions before 1.1.5, and Netscape 8.1 and earlier allow user-assisted remote attackers to read arbitrary files by tricking a user into typing the characters of the target filename in a text box and using the OnKeyDown, OnKeyPress, and OnKeyUp Javascript keystroke events to change the focus and cause those characters to be inserted into a file upload input control, which can then upload the file when the user submits the form.

    Source:Jesse Ruderman
    Published:7 Jun 2006
    4.3
    Medium

    CVE-2006-2892

    Last Modified: 31 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in GANTTy 1.0.3 allows remote attackers to inject arbitrary HTML and web script via the message parameter in a login action.

    Source:Luny
    Published:7 Jun 2006
    5.1
    Medium

    CVE-2006-2889

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in index.php in Pixelpost 1-5rc1-2 and earlier allow remote attackers to execute arbitrary SQL commands, and leverage them to gain administrator privileges, via the (1) category or (2) archivedate parameter.

    Source:rgod
    Published:7 Jun 2006
    7.5
    High

    CVE-2006-2888

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the WK[wkPath] parameter.

    Source:Kacper
    Published:7 Jun 2006
    7.5
    High

    CVE-2006-2887

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in myNewsletter 1.1.2 and earlier allow remote attackers to execute arbitrary SQL commands via the UserName parameter in (1) validatelogin.asp or (2) adminlogin.asp.

    Source:FarhadKey
    Published:7 Jun 2006
    7.5
    High

    CVE-2006-2884

    Last Modified: 31 Aug 2013

    SQL injection vulnerability in index.php in Kmita FAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the catid parameter.

    Source:Luny
    Published:7 Jun 2006
    4.3
    Medium

    CVE-2006-2883

    Last Modified: 31 Aug 2013

    Cross-site scripting (XSS) vulnerability in search.php in Kmita FAQ 1.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:Luny
    Published:7 Jun 2006
    5.1
    Medium

    CVE-2006-2881

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the da_path parameter in the (1) auth.cookie.inc.php, (2) auth.header.inc.php, or (3) auth.sessions.inc.php scripts.

    Source:Aesthetico
    Published:7 Jun 2006
    7.5
    High

    CVE-2006-2877

    Last Modified: 31 Aug 2013

    PHP remote file inclusion vulnerability in Bookmark4U 2.0.0 and earlier allows remote attackers to include arbitrary PHP files via the include_prefix parameter in (1) inc/dbase.php, (2) inc/config.php, (3) inc/common.php, and (4) inc/function.php. NOTE: it has been reported that the inc directory is protected by a .htaccess file, so this issue only applies in certain environments or configurations.

    Source:SnIpEr_SA
    Published:7 Jun 2006
    7.5
    High

    CVE-2006-2875

    Last Modified: 15 Nov 2017

    Stack-based buffer overflow in the CL_ParseDownload function of Quake 3 Engine 1.32c and earlier, as used in multiple products, allows remote attackers to execute arbitrary code via a svc_download command with compressed data that triggers the overflow during expansion.

    Source:Luigi Auriemma
    Published:7 Jun 2006
    4.3
    Medium

    CVE-2006-2873

    Last Modified: 30 Aug 2013

    Cross-site scripting (XSS) vulnerability in hava.asp in Enigma Haber 4.2 allows remote attackers to inject arbitrary web script or HTML via the il parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:The_BeKiR
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2871

    Last Modified: 31 Aug 2013

    PHP remote file inclusion vulnerability in include/common.php in CyBoards PHP Lite 1.25 allows remote attackers to execute arbitrary PHP code via a URL in the script_path parameter. NOTE: CVE disputes this issue, since $script_path is set to a constant value

    Source:SpC-x
    Published:6 Jun 2006
    5.1
    Medium

    CVE-2006-2868

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP code via a URL in the includePath cookie to (1) auth/extauth/drivers/mambo.inc.php or (2) auth/extauth/drivers/postnuke.inc.php.

    Source:rgod
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2867

    Last Modified: 30 Aug 2013

    SQL injection vulnerability in editpost.php in CoolForum 0.8.3 beta and earlier allows remote attackers to execute arbitrary SQL commands via the post parameter.

    Source:DarkFig
    Published:6 Jun 2006
    5.1
    Medium

    CVE-2006-2866

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in layout/prepend.php in DotClear 1.2.4 and earlier allows remote attackers to execute arbitrary PHP code via a FTP URL in the blog_dc_path parameter, which passes file_exists() and is_dir() tests on PHP 5.

    Source:rgod
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2865

    Last Modified: 30 Aug 2013

    PHP remote file inclusion vulnerability in template.php in phpBB 2 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter. NOTE: followup posts have disputed this issue, stating that template.php does not appear in phpBB and does not use a $page variable. It is possible that this is a site-specific vulnerability, or an issue in a mod

    Source:Canberx
    Published:6 Jun 2006
    5.1
    Medium

    CVE-2006-2864

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrary PHP code via a URL in the (1) APP[path][applications] parameter to (a) Bs_Faq.class.php, (2) APP[path][core] parameter to (b) fileBrowserInner.php, (c) file.php, and (d) viewer.php, and (e) Bs_ImageArchive.class.php, (3) GLOBALS[APP][path][core] parameter to (f) Bs_Ml_User.class.php, or (4) APP[path][plugins] parameter to (g) Bs_Wse_Profile.class.php.

    Source:Kacper
    Published:6 Jun 2006
    5.1
    Medium

    CVE-2006-2863

    Last Modified: 4 Oct 2016

    PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

    Source:Kacper
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2861

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.php in Particle Wiki 1.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.

    Source:FarhadKey
    Published:6 Jun 2006
    6.4
    Medium

    CVE-2006-2860

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) inc/logincheck.inc.php, (2) inc/adminheader.inc.php, (3) inc/global.php, or (4) inc/mainheader.inc.php. NOTE: some of these vectors were also reported for 3.0 in a separate disclosure.

    Source:Kacper
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2858

    Last Modified: 30 Aug 2013

    SQL injection vulnerability in viewmsg.asp in LocazoList Classifieds 1.05e allows remote attackers to execute arbitrary SQL commands via the msgid parameter.

    Source:ajann
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2857

    Last Modified: 16 Aug 2016

    SQL injection vulnerability in index.php in LifeType 1.0.4 allows remote attackers to execute arbitrary SQL commands via the articleId parameter in a ViewArticle action (viewarticleaction.class.php).

    Source:rgod
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2855

    Last Modified: 30 Aug 2013

    SQL injection vulnerability in index.php in xueBook 1.0 allows remote attackers to execute arbitrary SQL commands via the start parameter.

    Source:SpC-x
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2854

    Last Modified: 30 Aug 2013

    SQL injection vulnerability in index.php in iBWd Guestbook 1.0 allows remote attackers to execute arbitrary SQL commands via the offset parameter.

    Source:SpC-x
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2853

    Last Modified: 29 Aug 2013

    SQL injection vulnerability in content.php in abarcar Realty Portal 5.1.5 allows remote attackers to execute arbitrary SQL commands via the cat parameter.

    Source:SpC-x
    Published:6 Jun 2006
    6.8
    Medium

    CVE-2006-2852

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in dotWidget CMS 1.0.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the file_path parameter in (1) index.php, (2) feedback.php, and (3) printfriendly.php.

    Source:Aesthetico
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2849

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attackers to execute arbitrary PHP code via a URL in the bhconfig[bhfilepath] parameter.

    Source:beford
    Published:6 Jun 2006
    5
    Medium

    CVE-2006-2848

    Last Modified: 16 Apr 2026

    links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct request with a modified txtAdministrativePassword field.

    Source:ajann
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2847

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in links.asp in aspWebLinks 2.0 allows remote attackers to execute arbitrary SQL commands via the linkID parameter.

    Source:ajann
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2845

    Last Modified: 3 Nov 2016

    PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to image_resize/pages/index.inc.php.

    Source:beford
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2844

    Last Modified: 3 Nov 2016

    Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code via a URL in the REX[INCLUDE_PATH] parameter to (1) simple_user/pages/index.inc.php and (2) stats/pages/index.inc.php.

    Source:beford
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2843

    Last Modified: 3 Nov 2016

    PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL in the (1) REX[INCLUDE_PATH] parameter in (a) addons/import_export/pages/index.inc.php and (b) pages/community.inc.php.

    Source:beford
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2842

    Last Modified: 30 Aug 2013

    PHP remote file inclusion vulnerability in functions/plugin.php in SquirrelMail 1.4.6 and earlier, if register_globals is enabled and magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the plugins array parameter. NOTE: this issue has been disputed by third parties, who state that Squirrelmail provides prominent warnings to the administrator when register_globals is enabled. Since the varieties of administrator negligence are uncountable, perhaps this type of issue should not be included in CVE. However, the original developer has posted a security advisory, so there might be relevant real-world environments under which this vulnerability is applicable

    Source:brokejunker
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2841

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute arbitrary PHP code via a URL in the root_path parameter to (1) menu.php, (2) profile.php, (3) users.php, (4) cache_mngt.php, and (5) gallery_functions.php.

    Source:Kacper
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2835

    Last Modified: 11 Sept 2013

    SQL injection vulnerability in saphplesson 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) forumid parameter in add.php and (2) lessid parameter in show.php.

    Source:C.B.B.L
    Published:6 Jun 2006
    7.5
    High

    CVE-2006-2834

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:SmokeZ
    Published:6 Jun 2006
    6.4
    Medium

    CVE-2006-2828

    Last Modified: 16 Apr 2026

    Global variable overwrite vulnerability in PHP-Nuke allows remote attackers to conduct remote PHP file inclusion attacks via a modified phpbb_root_path parameter to the admin scripts (1) index.php, (2) admin_ug_auth.php, (3) admin_board.php, (4) admin_disallow.php, (5) admin_forumauth.php, (6) admin_groups.php, (7) admin_ranks.php, (8) admin_styles.php, (9) admin_user_ban.php, (10) admin_words.php, (11) admin_avatar.php, (12) admin_db_utilities.php, (13) admin_forum_prune.php, (14) admin_forums.php, (15) admin_mass_email.php, (16) admin_smilies.php, (17) admin_ug_auth.php, and (18) admin_users.php, which overwrites $phpbb_root_path when the import_request_variables function is executed after $phpbb_root_path has been initialized to a static value.

    Source:ddoshomo
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2826

    Last Modified: 19 Jan 2018

    SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute arbitrary SQL commands via the id variable, which is set by a client through a query string or a cookie.

    Source:GulfTech Security
    Published:5 Jun 2006
    6.8
    Medium

    CVE-2006-2821

    Last Modified: 30 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DeltaScripts Pro Publish allow remote attackers to inject arbitrary web script or HTML via the (1) artid parameter in art.php and the (2) catname parameter in cat.php.

    Source:Soot
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2819

    Last Modified: 16 Aug 2016

    PHP remote file inclusion vulnerability in Wiki.php in Barnraiser Igloo 0.1.9 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the c_node[class_path] parameter.

    Source:Kacper
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2818

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to execute arbitrary PHP code via a URL in the CONF[local_path] parameter.

    Source:Kacper
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2817

    Last Modified: 29 Aug 2013

    SQL injection vulnerability in bolum.php in tekno.Portal allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:SpC-x
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2814

    Last Modified: 16 Apr 2026

    Multiple buffer overflows in the (1) vGetPost and (2) main functions in easy-scart.c through easy-scart6.c in iShopCart allow remote attackers to execute arbitrary code by sending a large amount of data containing "Submit" in an sslinvoice action, and allow remote attackers to have an unknown impact via a large amount of posted data.

    Source:K-sPecial
    Published:5 Jun 2006
    7.5
    High

    CVE-2006-2811

    Last Modified: 30 Aug 2013

    Multiple PHP remote file inclusion vulnerabilities in Cantico Ovidentia 5.8.0 allow remote attackers to execute arbitrary PHP code via a URL in the babInstallPath parameter in (1) index.php, (2) topman.php, (3) approb.php, (4) vacadmb.php, (5) vacadma.php, (6) vacadm.php, (7) statart.php, (8) search.php, (9) posts.php, (10) options.php, (11) login.php, (12) frchart.php, (13) flbchart.php, (14) fileman.php, (15) faq.php, (16) event.php, (17) directory.php, (18) articles.php, (19) artedit.php, (20) calday.php, and additional unspecified PHP scripts. NOTE: the utilit.php vector is already covered by CVE-2005-1964.

    Source:black-cod3
    Published:5 Jun 2006
    10
    Critical

    CVE-2006-2807

    Last Modified: 16 Apr 2026

    ASPwebSoft Speedy Asp Discussion Forum allows remote attackers to change the password of any account via a modified account id and possibly arbitrary values of the name, email, country, password, and passwordre parameters to profileupdate.asp.

    Source:ajann
    Published:5 Jun 2006