5
    Medium

    CVE-2006-2805

    Last Modified: 29 Aug 2013

    SQL injection vulnerability in VBulletin 3.0.10 allows remote attackers to execute arbitrary SQL commands via the featureid parameter.

    Source:SpC-x
    Published:3 Jun 2006
    6.8
    Medium

    CVE-2006-2803

    Last Modified: 30 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in PHP ManualMaker 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) id parameter to index.php, (2) search field (possibly the s parameter), or (3) comment field.

    Source:Luny
    Published:3 Jun 2006
    5
    Medium

    CVE-2006-2802

    Last Modified: 29 Jul 2016

    Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial of service (application crash) via a long reply from an HTTP server, as demonstrated using gxine 0.5.6.

    Source:Federico L. Bossi Bonin
    Published:3 Jun 2006
    6.8
    Medium

    CVE-2006-2798

    Last Modified: 16 Apr 2026

    Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) LoName parameter in (a) week.php and (b) month.php and (2) AddressLink parameter in (c) event.php.

    Source:X0r_1
    Published:3 Jun 2006
    7.5
    High

    CVE-2006-2797

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to execute arbitrary SQL commands via the (1) CalendarDetailsID parameter in (a) month.php, (b) day.php, and (c) delCalendar.php; (2) ID parameter in (d) event.php; (3) AdminUserID parameter in (e) delAdmin.php; (4) EventLocationID parameter in (f) delAddress.php; and (5) LocationID parameter in (g) delCategory.php.

    Source:X0r_1
    Published:3 Jun 2006
    7.8
    High

    CVE-2006-2794

    Last Modified: 16 Apr 2026

    Hesabim.asp in ASPSitem 2.0 and earlier allows remote attackers to read private messages of other users via a modified id parameter.

    Source:nukedx
    Published:3 Jun 2006
    7.5
    High

    CVE-2006-2793

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Anket.asp in ASPSitem 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.

    Source:nukedx
    Published:3 Jun 2006
    6.4
    Medium

    CVE-2006-2771

    Last Modified: 29 Aug 2013

    admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attackers to delete arbitrary posts via a modified delID parameter.

    Source:omnipresent
    Published:2 Jun 2006
    5.4
    Medium

    CVE-2006-2770

    Last Modified: 2 Jan 2017

    Directory traversal vulnerability in randompic.php in pppBLOG 0.3.8 and earlier, when register_globals is enabled, allows remote attackers to read arbitrary files via a .. (dot dot) sequence in an index of the "file" array parameter, as demonstrated by file[0].

    Source:JosS
    Published:2 Jun 2006
    5
    Medium

    CVE-2006-2769

    Last Modified: 29 Aug 2013

    The HTTP Inspect preprocessor (http_inspect) in Snort 2.4.0 through 2.4.4 allows remote attackers to bypass "uricontent" rules via a carriage return (\r) after the URL and before the HTTP declaration.

    Source:Blake Hartstein
    Published:2 Jun 2006
    5.1
    Medium

    CVE-2006-2768

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the (1) system_path parameter in a large number of files in the (a) app/edocument/, (b) app/eproject/, (c) app/erek/, and (d) extension/ directories, and the (2) GLOBALS[system_path] parameter in (e) extension/sitemap/sitemap.datatype.php.

    Source:Kacper
    Published:2 Jun 2006
    5.1
    Medium

    CVE-2006-2767

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the default_path parameter in (1) error.php, (2) index.php, and (3) classes/main_class.php.

    Source:Kacper
    Published:2 Jun 2006
    2.6
    Low

    CVE-2006-2766

    Last Modified: 29 Aug 2013

    Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook Express 6, and possibly other programs, allows remote user-assisted attackers to cause a denial of service (application crash) via a long mhtml URI in the URL value in a URL file.

    Source:Mr.Niega
    Published:2 Jun 2006
    6.4
    Medium

    CVE-2006-2763

    Last Modified: 6 Dec 2016

    SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) index.php, and the (2) nid parameter to (b) news_detail.php, (c) email_story.php, (d) thankyou.php, (e) printable_view.php, (f) tella_friend.php, and (g) send_comments.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. It is possible that this is primary to CVE-2006-2678.

    Source:K-159
    Published:2 Jun 2006
    5.3
    Medium

    CVE-2006-2758

    Last Modified: 7 Mar 2012

    Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %2e%2e%5c (encoded ../) in the URL. NOTE: this might be the same issue as CVE-2005-3747.

    Source:LiquidWorm
    Published:18 Nov 2005
    4.3
    Medium

    CVE-2006-2755

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject arbitrary web script or HTML via the debug parameter, as demonstrated by stealing MD5 hashes of passwords.

    Source:nukedx
    Published:2 Jun 2006
    5.1
    Medium

    CVE-2006-2747

    Last Modified: 29 Aug 2013

    Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrary files or execute PHP code via a .. (dot dot) sequence and trailing null (%00) byte in the subsite parameter in a showsubsite todo.

    Source:darkgod
    Published:1 Jun 2006
    6.8
    Medium

    CVE-2006-2746

    Last Modified: 29 Jul 2016

    Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao. NOTE: vectors 2 and 3 might be resultant from file inclusion issues.

    Source:nukedx
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2745

    Last Modified: 29 Jul 2016

    Multiple PHP remote file inclusion vulnerabilities in F@cile Interactive Web 0.8.5 and earlier, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) pathfile parameter in (a) p-editpage.php and (b) p-editbox.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao.

    Source:nukedx
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2744

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in p-popupgallery.php in F@cile Interactive Web 0.8.41 through 0.8.5 allows remote attackers to execute arbitrary PHP code via a URL in the l parameter.

    Source:nukedx
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2743

    Last Modified: 22 Nov 2017

    Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple extensions, which allows remote attackers to upload, modify, or execute arbitrary files in the files directory.

    Source:rgod
    Published:1 Jun 2006
    6.8
    Medium

    CVE-2006-2740

    Last Modified: 14 Nov 2016

    Multiple SQL injection vulnerabilities in Epicdesigns tinyBB 0.3 allow remote attackers to execute arbitrary SQL commands via the (1) q parameter in (a) forgot.php, and the (2) username and (3) password parameters in (b) login.php, and other unspecified vectors.

    Source:nukedx
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2739

    Last Modified: 14 Nov 2016

    PHP remote file inclusion vulnerability in footers.php in Epicdesigns tinyBB 0.3, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the tinybb_footers parameter.

    Source:nukedx
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2737

    Last Modified: 5 Jan 2017

    utilities/register.asp in Nukedit 4.9.6 and earlier allows remote attackers to create new users as part of arbitrary groups, including the administrative group, via a modified groupid parameter when creating a user via the addDB action.

    Source:FarhadKey
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2736

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in blend_data/blend_common.php in Blend Portal 1.2.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507.

    Source:nukedx
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2735

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in language/lang_english/lang_activity.php in Activity MOD Plus (Amod) 1.1.0, as used with phpBB when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. NOTE: This is a similar vulnerability to CVE-2006-2507.

    Source:nukedx
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2732

    Last Modified: 28 Aug 2013

    SQL injection vulnerability in Your_Account.asp in Mini-Nuke 2.3 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) yas_1, (2) yas_2, and (3) yas_3 parameters.

    Source:Mustafa Can Bjorn
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2731

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Enigma Haber 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in (a) e_mesaj_yas.asp, (b) edi_haber.asp, and (c) haber_devam.asp; (2) hid parameter in (d) yazdir.asp and (e) yorum.asp, and the (3) e parameter in (f) arsiv.asp. NOTE: with administrator credentials, additional vectors exist including (4) yid parameter to (g) admin/y_admin.asp, (5) bid parameter to (h) admin/reklam_detay.asp, hid parameter to (i) admin/detay_yorum.asp and (j) admin/haber_sil.asp, (6) kid parameter to (k) admin/kategori_d.asp, (7) tur parameter to (l) admin/haber_ekle.asp, (8) s parameter to (m) admin/e_mesaj_yaz.asp, and id parameter to (n) admin/admin_sil.asp.

    Source:nukedx
    Published:1 Jun 2006
    5.1
    Medium

    CVE-2006-2730

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when register_globals is enabled, allows remote attackers to include arbitrary files via the GLOBALS[CLASS_PATH] parameter. NOTE: this issue might be resultant from a global overwrite vulnerability.

    Source:Kacper
    Published:1 Jun 2006
    2.6
    Low

    CVE-2006-2728

    Last Modified: 29 Aug 2013

    Cross-site scripting (XSS) vulnerability in superalbum/index.php in Photoalbum B&W 1.3 allows remote attackers to inject arbitrary web script or HTML via the pic parameter.

    Source:black-code
    Published:1 Jun 2006
    7.5
    High

    CVE-2006-2726

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files via the config[fsBase] parameter in (1) drucken.php, (2) drucken2.php, (3) email_an_benutzer.php, (4) rechnung.php, (5) suche/search.php and (6) adminbereich/admin.php.

    Source:Kacper
    Published:1 Jun 2006
    6.4
    Medium

    CVE-2006-2725

    Last Modified: 11 Jan 2017

    SQL injection vulnerability in rss/posts.php in Eggblog before 3.07 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:nukedx
    Published:1 Jun 2006
    5
    Medium

    CVE-2006-2723

    Last Modified: 16 Apr 2026

    Unspecified versions of Mozilla Firefox allow remote attackers to cause a denial of service (crash) via a web page that contains a large number of nested marquee tags. NOTE: a followup post indicated that the initial report could not be verified.

    Source:n00b
    Published:1 Jun 2006
    6.8
    Medium

    CVE-2006-2699

    Last Modified: 29 Aug 2013

    Cross-site scripting (XSS) vulnerability in getimage.php in Geeklog 1.4.0sr2 and earlier allows remote attackers to inject arbitrary HTML or web script via the image argument in a show action.

    Source:trueend5
    Published:31 May 2006
    6.4
    Medium

    CVE-2006-2697

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) startletter parameter in userview.asp and the (2) forumname parameter in topics.asp.

    Source:ajann
    Published:31 May 2006
    6.8
    Medium

    CVE-2006-2696

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerabilities in Easy-Content Forums 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) startletter parameter in userview.asp and the (2) catid parameter in topics.asp.

    Source:ajann
    Published:31 May 2006
    6.8
    Medium

    CVE-2006-2689

    Last Modified: 29 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in EVA-Web 2.1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) debut_image parameter in (a) article-album.php3, (2) date parameter in (b) rubrique.php3, and the (3) perso and (4) aide parameters to (c) an unknown script, probably index.php.

    Source:r0t
    Published:31 May 2006
    6.4
    Medium

    CVE-2006-2686

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[AA_INC_PATH] parameter in (1) cached.php3, (2) cron.php3, (3) discussion.php3, (4) filldisc.php3, (5) filler.php3, (6) fillform.php3, (7) go.php3, (8) hiercons.php3, (9) jsview.php3, (10) live_checkbox.php3, (11) offline.php3, (12) post2shtml.php3, (13) search.php3, (14) slice.php3, (15) sql_update.php3, (16) view.php3, (17) multiple files in the (18) admin/ folder, (19) includes folder, and (20) modules/ folder.

    Source:Kacper
    Published:31 May 2006
    4
    Medium

    CVE-2006-2685

    Last Modified: 24 Nov 2017

    PHP remote file inclusion vulnerability in Basic Analysis and Security Engine (BASE) 1.2.4 and earlier, with register_globals enabled, allows remote attackers to execute arbitrary PHP code via a URL in the BASE_path parameter to (1) base_qry_common.php, (2) base_stat_common.php, and (3) includes/base_include.inc.php.

    Source:Metasploit
    Published:31 May 2006
    6.4
    Medium

    CVE-2006-2683

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary PHP code via a URL in the REDSYS[MYPATH][TEMPLATES] parameter.

    Source:Kacper
    Published:31 May 2006
    6.4
    Medium

    CVE-2006-2682

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the _PSL[classdir] parameter.

    Source:Kacper
    Published:31 May 2006
    6.8
    Medium

    CVE-2006-2681

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in SocketMail Lite and Pro 2.2.6 and earlier, when register_globals and magic_quotes are enabled, allows remote attackers to execute arbitrary PHP code via a URL in the site_path parameter to (1) index.php and (2) inc-common.php.

    Source:Aesthetico
    Published:31 May 2006
    5.8
    Medium

    CVE-2006-2680

    Last Modified: 31 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in AZ Photo Album Script Pro allows remote attackers to inject arbitrary web script or HTML via the gazpart parameter.

    Source:Luny
    Published:31 May 2006
    5.1
    Medium

    CVE-2006-2675

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in ubbt.inc.php in UBBThreads 5.x and 6.x allows remote attackers to execute arbitrary PHP code via a URL in the (1) thispath or (2) configdir parameters.

    Source:nukedx
    Published:30 May 2006
    7.5
    High

    CVE-2006-2668

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Docebo LMS 2.05 allow remote attackers to execute arbitrary PHP code via a URL in the lang parameter to (1) modules/credits/business.php, (2) modules/credits/credits.php, or (3) modules/credits/help.php.

    Source:beford
    Published:30 May 2006
    7.5
    High

    CVE-2006-2667

    Last Modified: 21 Apr 2020

    Direct static code injection vulnerability in WordPress 2.0.2 and earlier allows remote attackers to execute arbitrary commands by inserting a carriage return and PHP code when updating a profile, which is appended after a special comment sequence into files in (1) wp-content/cache/userlogins/ (2) wp-content/cache/users/ which are later included by cache.php, as demonstrated using the displayname argument.

    Source:rgod
    Published:30 May 2006
    7.5
    High

    CVE-2006-2666

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in includes/mailaccess/pop3.php in V-Webmail 1.5 through 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.

    Source:beford
    Published:30 May 2006
    7.5
    High

    CVE-2006-2665

    Last Modified: 29 Jul 2016

    PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the CONFIG[pear_dir] parameter.

    Source:beford
    Published:30 May 2006
    5
    Medium

    CVE-2006-2661

    Last Modified: 17 Sept 2013

    ftutil.c in Freetype before 2.2 allows remote attackers to cause a denial of service (crash) via a crafted font file that triggers a null dereference.

    Source:Josh Bressers
    Published:15 May 2006
    7.5
    High

    CVE-2006-2656

    Last Modified: 29 Jul 2016

    Stack-based buffer overflow in the tiffsplit command in libtiff 3.8.2 and earlier might might allow attackers to execute arbitrary code via a long filename. NOTE: tiffsplit is not setuid. If there is not a common scenario under which tiffsplit is called with attacker-controlled command line arguments, then perhaps this issue should not be included in CVE.

    Source:nitr0us
    Published:25 May 2006