2.1
    Low

    CVE-2006-2334

    Last Modified: 25 Aug 2013

    The RtlDosPathNameToNtPathName_U API function in NTDLL.DLL in Microsoft Windows 2000 SP4 and XP SP2 does not properly convert DOS style paths with trailing spaces into NT style paths, which allows context-dependent attackers to create files that cannot be accessed through the expected DOS path or prevent access to other similarly named files in the same directory, which prevents those files from being detected or disinfected by certain anti-virus and anti-spyware software.

    Source:Mario Ballano Bárcena
    Published:12 May 2006
    6.4
    Medium

    CVE-2006-2331

    Last Modified: 20 Jul 2016

    Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (dot dot) in the settings[locale] parameter in infusions/last_seen_users_panel/last_seen_users_panel.php, and (2) a .. (dot dot) in the localeset parameter in setup.php. NOTE: the vendor states that this issue might exist due to problems in third party local files.

    Source:rgod
    Published:12 May 2006
    6.4
    Medium

    CVE-2006-2330

    Last Modified: 20 Jul 2016

    PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

    Source:rgod
    Published:12 May 2006
    5.1
    Medium

    CVE-2006-2323

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in SmartISoft phpListPro 2.01 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the returnpath parameter in (1) editsite.php, (2) addsite.php, and (3) in.php. NOTE: The config.php vector is already covered by CVE-2006-1749.

    Source:Aesthetico
    Published:12 May 2006
    4.9
    Medium

    CVE-2006-2316

    Last Modified: 16 Apr 2026

    S24EvMon.exe in the Intel PROset/Wireless software, possibly 10.1.0.33, uses a S24EventManagerSharedMemory shared memory section with weak permissions, which allows local users to read or modify passwords or other data, or cause a denial of service.

    Source:Ruben Santamarta
    Published:12 May 2006
    7.5
    High

    CVE-2006-2315

    Last Modified: 25 Aug 2013

    PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled

    Source:ReZEN
    Published:12 May 2006
    5
    Medium

    CVE-2006-2310

    Last Modified: 5 Sept 2013

    BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to cause a denial of service (hang) via a request for a .cfm file whose name contains an MS-DOS device name such as (1) con, (2) aux, (3) com1, and (4) com2.

    Source:Tan Chew Keong
    Published:26 Jun 2006
    9.3
    Critical

    CVE-2006-2306

    Last Modified: 25 Aug 2013

    Cross-site scripting (XSS) vulnerability in moreinfo.asp in EPublisherPro allows remote attackers to inject arbitrary web script or HTML via the title parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Dj_Eyes
    Published:11 May 2006
    7.5
    High

    CVE-2006-2300

    Last Modified: 27 Oct 2016

    Multiple SQL injection vulnerabilities in EImagePro allow remote attackers to execute arbitrary SQL commands via the (1) CatID parameter to subList.asp, (2) SubjectID parameter to imageList.asp, or (3) Pic parameter to view.asp.

    Source:Dj_Eyes
    Published:11 May 2006
    4
    Medium

    CVE-2006-2297

    Last Modified: 2 Sept 2013

    Heap-based buffer overflow in Microsoft Infotech Storage System Library (itss.dll) allows user-assisted attackers to execute arbitrary code via a crafted CHM / ITS file that triggers the overflow while decompiling.

    Source:Ruben Santamarta
    Published:10 May 2006
    6.4
    Medium

    CVE-2006-2296

    Last Modified: 25 Aug 2013

    SQL injection vulnerability in search_result.asp in EDirectoryPro 2.0 and earlier allows remote attackers to execute arbitrary SQL commands via the keyword parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Dj_Eyes
    Published:9 May 2006
    7.5
    High

    CVE-2006-2295

    Last Modified: 25 Aug 2013

    Directory traversal vulnerability in Dynamic Galerie 1.0 allows remote attackers to access arbitrary files via an absolute path in the pfad parameter to (1) index.php and (2) galerie.php.

    Source:d4igoro
    Published:9 May 2006
    6.8
    Medium

    CVE-2006-2294

    Last Modified: 25 Aug 2013

    Cross-site scripting (XSS) vulnerability in Dynamic Galerie 1.0 allows remote attackers to inject arbitrary web script or HTML via the pfad parameter in (1) index.php and (2) galerie.php. NOTE: this issue might be resultant from directory traversal.

    Source:d4igoro
    Published:9 May 2006
    6.4
    Medium

    CVE-2006-2293

    Last Modified: 25 Aug 2013

    SQL injection vulnerability in all_calendars.asp in MultiCalendars 3.0 allows remote attackers to execute arbitrary SQL commands via the calsids parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:Dj_Eyes
    Published:9 May 2006
    5.1
    Medium

    CVE-2006-2285

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in authldap.php in Dokeos 1.6.4 allows remote attackers to execute arbitrary PHP code via a URL in the includePath parameter.

    Source:beford
    Published:9 May 2006
    6.8
    Medium

    CVE-2006-2284

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP code via a URL in the (1) clarolineRepositorySys parameter in ldap.inc.php and the (2) claro_CasLibPath parameter in casProcess.inc.php.

    Source:beford
    Published:9 May 2006
    5
    Medium

    CVE-2006-2280

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in website.php in openEngine 1.8 Beta 2 and earlier allows remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the template parameter.

    Published:9 May 2006
    5
    Medium

    CVE-2006-2277

    Last Modified: 27 Aug 2013

    Multiple Apple Mac OS X 10.4 applications might allow context-dependent attackers to cause a denial of service (application crash) via a crafted OpenEXR (.exr) image file, which triggers the crash when opening a folder using Finder, displaying the image in Safari, or using Preview to open the file.

    Source:Christian
    Published:9 May 2006
    7.5
    High

    CVE-2006-2270

    Last Modified: 20 Jul 2016

    PHP remote file inclusion vulnerability in includes/config.php in Jetbox CMS 2.1 allows remote attackers to execute arbitrary code via a URL in the relative_script_path parameter.

    Source:beford
    Published:9 May 2006
    4.3
    Medium

    CVE-2006-2269

    Last Modified: 14 Dec 2016

    Cross-site scripting (XSS) vulnerability in myWebland MyBloggie 2.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via a JavaScript event in a BBCode img tag.

    Source:zerogue
    Published:9 May 2006
    2.6
    Low

    CVE-2006-2265

    Last Modified: 25 Aug 2013

    Cross-site scripting vulnerability in admin/main.asp in Ocean12 Calendar Manager Pro 1.00 allows remote attackers to inject arbitrary web script or HTML via the date parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:dj_eyes2005
    Published:9 May 2006
    6.5
    Medium

    CVE-2006-2264

    Last Modified: 25 Aug 2013

    Multiple SQL injection vulnerabilities in Ocean12 Calendar Manager Pro 1.00 allow remote attackers to execute arbitrary SQL commands via the (1) date parameter to admin/main.asp, (2) SearchFor parameter to admin/view.asp, or (3) ID parameter to admin/edit.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:dj_eyes2005
    Published:9 May 2006
    7.5
    High

    CVE-2006-2263

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands via the cid parameter.

    Source:tracewar
    Published:9 May 2006
    2.6
    Low

    CVE-2006-2262

    Last Modified: 24 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in singapore 0.9.7 allows remote attackers to inject arbitrary web script or HTML via the image parameter.

    Published:9 May 2006
    7.5
    High

    CVE-2006-2261

    Last Modified: 18 Apr 2015

    PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code via a URL in the path parameter.

    Source:PiNGuX
    Published:9 May 2006
    6.4
    Medium

    CVE-2006-2256

    Last Modified: 29 Nov 2016

    PHP remote file inclusion vulnerability in includes/dbal.php in EQdkp 1.3.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the eqdkp_root_path parameter.

    Source:OLiBekaS
    Published:9 May 2006
    7.5
    High

    CVE-2006-2255

    Last Modified: 25 Aug 2013

    Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.

    Source:r0t
    Published:9 May 2006
    5
    Medium

    CVE-2006-2254

    Last Modified: 16 Apr 2026

    Buffer overflow in filecpnt.exe in FileCOPA 1.01 allows remote attackers to cause a denial of service (application crash) via a username with a large number of newline characters.

    Source:Bigeazer
    Published:9 May 2006
    7.5
    High

    CVE-2006-2253

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute arbitrary PHP code via a URL in the statitpath parameter.

    Source:IGNOR3
    Published:9 May 2006
    6.4
    Medium

    CVE-2006-2252

    Last Modified: 24 Aug 2013

    Cross-site scripting vulnerability in submit.php in OpenFAQ 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the q parameter.

    Source:Kamil Sienicki
    Published:9 May 2006
    4.3
    Medium

    CVE-2006-2249

    Last Modified: 24 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in search.php in CuteNews 1.4.1 and earlier, and possibly 1.4.5, allow remote attackers to inject arbitrary web script or HTML via the (1) user, (2) story, or (3) title parameters.

    Source:NST
    Published:9 May 2006
    6.8
    Medium

    CVE-2006-2245

    Last Modified: 20 Jul 2016

    PHP remote file inclusion vulnerability in auction\auction_common.php in Auction mod 1.3m for phpBB allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter.

    Source:webDEViL
    Published:9 May 2006
    5
    Medium

    CVE-2006-2242

    Last Modified: 20 Jul 2016

    acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) characters to the USER command.

    Source:Preddy
    Published:9 May 2006
    6.4
    Medium

    CVE-2006-2241

    Last Modified: 29 Dec 2016

    PHP remote file inclusion vulnerability in show.php in Fast Click SQL Lite 1.1.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: This is a different vulnerability than CVE-2006-2175.

    Source:R@1D3N
    Published:9 May 2006
    5.1
    Medium

    CVE-2006-2237

    Last Modified: 16 Apr 2026

    The web interface for AWStats 6.4 and 6.5, when statistics updates are enabled, allows remote attackers to execute arbitrary code via shell metacharacters in the migrate parameter.

    Source:patrick
    Published:8 May 2006
    7.6
    High

    CVE-2006-2236

    Last Modified: 20 Jul 2016

    Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III Arena 1.32b allows remote attackers to execute arbitrary commands via a long remapShader command.

    Source:landser
    Published:8 May 2006
    7.5
    High

    CVE-2006-2233

    Last Modified: 24 Aug 2013

    Buffer overflow in BankTown Client Control (aka BtCxCtl20Com) 1.4.2.51817, and possibly 1.5.2.50209, allows remote attackers to execute arbitrary code via a long string in the first argument to SetBannerUrl. NOTE: portions of these details are obtained from third party information.

    Source:Gyu Tae
    Published:5 May 2006
    5
    Medium

    CVE-2006-2230

    Last Modified: 23 Aug 2013

    Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.4 might allow attackers to cause a denial of service via format string specifiers in an MP3 filename specified on the command line. NOTE: this is a different vulnerability than CVE-2006-1905. In addition, if the only attack vectors involve a user-assisted, local command line argument of a non-setuid program, this issue might not be a vulnerability.

    Source:KaDaL-X
    Published:5 May 2006
    4.3
    Medium

    CVE-2006-2228

    Last Modified: 22 Aug 2013

    Cross-site scripting (XSS) vulnerability in w-Agora (aka Web-Agora) 4.2.0 allows remote attackers to inject arbitrary web script or HTML via a post with a BBCode tag that contains a JavaScript event name followed by whitespace before the '=' (equals) character, which bypasses a restrictive regular expression that attempts to remove onmouseover and other events.

    Source:r0xes
    Published:5 May 2006
    5
    Medium

    CVE-2006-2226

    Last Modified: 16 Apr 2026

    Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of service via a long argument to the PORT command.

    Source:luka.research
    Published:5 May 2006
    7.5
    High

    CVE-2006-2225

    Last Modified: 27 Apr 2011

    Buffer overflow in XM Easy Personal FTP Server 4.3 and earlier allows remote attackers to execute arbitrary code, probably via a USER command with a long username.

    Source:rewterz
    Published:5 May 2006
    5
    Medium

    CVE-2006-2224

    Last Modified: 23 Aug 2013

    RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly enforce RIPv2 authentication requirements, which allows remote attackers to modify routing state via RIPv1 RESPONSE packets.

    Source:Konstantin V. Gavrilenko
    Published:3 May 2006
    5
    Medium

    CVE-2006-2223

    Last Modified: 23 Aug 2013

    RIPd in Quagga 0.98 and 0.99 before 20060503 does not properly implement configurations that (1) disable RIPv1 or (2) require plaintext or MD5 authentication, which allows remote attackers to obtain sensitive information (routing state) via REQUEST packets such as SEND UPDATE.

    Source:Konstantin V. Gavrilenko
    Published:3 May 2006
    5
    Medium

    CVE-2006-2222

    Last Modified: 16 Apr 2026

    Buffer overflow in zawhttpd 0.8.23, and possibly previous versions, allows remote attackers to cause a denial of service (daemon crash) via a request for a URI composed of several "\" (backslash) characters.

    Source:Kamil Sienicki
    Published:5 May 2006
    7.5
    High

    CVE-2006-2217

    Last Modified: 24 Aug 2013

    SQL injection vulnerability in index.php in Invision Power Board allows remote attackers to execute arbitrary SQL commands via the pid parameter in a reputation action. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:almaster
    Published:5 May 2006
    7.5
    High

    CVE-2006-2214

    Last Modified: 22 Aug 2013

    Multiple SQL injection vulnerabilities in 4images 1.7.1 and earlier allow remote attackers to execute arbitrary SQL commands via the sessionid parameter in (1) top.php and (2) member.php. NOTE: this issue has also been reported to affect 1.7.2.

    Source:CrAzY.CrAcKeR
    Published:5 May 2006
    6.4
    Medium

    CVE-2006-2212

    Last Modified: 1 Nov 2016

    Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.

    Source:Metasploit
    Published:5 May 2006
    5
    Medium

    CVE-2006-2211

    Last Modified: 23 Aug 2013

    Absolute path traversal vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to browse arbitrary directories via the path parameter.

    Source:d4igoro
    Published:5 May 2006
    5.8
    Medium

    CVE-2006-2210

    Last Modified: 23 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in 321soft PhP-Gallery 0.9 allows remote attackers to inject arbitrary web script or HTML via the path parameter. NOTE: this issue might be resultant from the directory traversal vulnerability.

    Source:d4igoro
    Published:5 May 2006
    6.4
    Medium

    CVE-2006-2209

    Last Modified: 24 Aug 2013

    Multiple SQL injection vulnerabilities in index.php in PHP Arena paCheckBook 1.1 allow remote attackers to execute arbitrary SQL commands via (1) the transtype parameter in an add action or (2) entry parameter in an edit action. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

    Source:almaster
    Published:5 May 2006