4.3
    Medium

    CVE-2006-2208

    Last Modified: 24 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in mynews.inc.php in MyNews 1.6.2 allow remote attackers to inject arbitrary web script or HTML via the (1) hash and (2) page parameters.

    Source:DreamLord
    Published:5 May 2006
    6.8
    Medium

    CVE-2006-2187

    Last Modified: 23 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in zenphoto 1.0.1 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) a parameter in i.php, and the (2) album and (3) image parameters in index.php.

    Source:zone14
    Published:4 May 2006
    6.4
    Medium

    CVE-2006-2182

    Last Modified: 16 Apr 2026

    Multiple PHP remote file inclusion vulnerabilities in (1) eday.php, (2) eshow.php, or (3) forgot.php in albinator 2.0.8 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the Config_rootdir parameter.

    Source:webDEViL
    Published:4 May 2006
    4.3
    Medium

    CVE-2006-2181

    Last Modified: 24 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Albinator 2.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) cid parameter to dlisting.php or (2) preloadSlideShow parameter to showpic.php.

    Source:r0t
    Published:4 May 2006
    6.4
    Medium

    CVE-2006-2180

    Last Modified: 16 Apr 2026

    Buffer overflow in Golden FTP Server Pro 2.70 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via a long argument to the (1) NLST or (2) APPE commands, as demonstrated by the Infigo FTPStress Fuzzer.

    Source:Jerome Athias
    Published:4 May 2006
    7.5
    High

    CVE-2006-2179

    Last Modified: 24 Aug 2013

    Multiple SQL injection vulnerabilities in CyberBuild allow remote attackers to execute arbitrary SQL commands via the (1) SessionID parameter to login.asp or (2) ProductIndex parameter to browse0.htm.

    Source:r0t
    Published:4 May 2006
    5.8
    Medium

    CVE-2006-2178

    Last Modified: 24 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp. NOTE: vectors 1 and 2 might be resultant from SQL injection.

    Source:r0t
    Published:4 May 2006
    4.3
    Medium

    CVE-2006-2177

    Last Modified: 23 Aug 2013

    Cross-site scripting (XSS) vulnerability in viewcat.php in geoBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the cat parameter.

    Source:SubjectZero
    Published:4 May 2006
    5.8
    Medium

    CVE-2006-2176

    Last Modified: 24 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in links.php in PHP Linkliste 1.0b allow remote attackers to inject arbitrary web script or HTML via the (1) new_input, (2) new_url, or (3) new_name parameter.

    Source:d4igoro
    Published:4 May 2006
    6.4
    Medium

    CVE-2006-2175

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) show.php or (2) top.php.

    Source:R@1D3N
    Published:4 May 2006
    4.3
    Medium

    CVE-2006-2174

    Last Modified: 23 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in admin/server_day_stats.php in Virtual Hosting Control System (VHCS) allow remote attackers to inject arbitrary web script or HTML via the (1) day, (2) month, or (3) year parameter.

    Source:O.U.T.L.A.W
    Published:4 May 2006
    2.6
    Low

    CVE-2006-2163

    Last Modified: 23 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in Pinnacle Cart 3.33 and earlier allows remote attackers to inject arbitrary web script or HTML via the setbackurl parameter.

    Source:r0t
    Published:4 May 2006
    6.4
    Medium

    CVE-2006-2156

    Last Modified: 23 Dec 2016

    Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitrary files via .. (dot dot) sequences in the help_file parameter.

    Source:rgod
    Published:3 May 2006
    7.5
    High

    CVE-2006-2152

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

    Source:[Oo]
    Published:3 May 2006
    7.5
    High

    CVE-2006-2151

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enabled, allows remote attackers to include arbitrary files via the phpbb_root_path parameter.

    Source:[Oo]
    Published:3 May 2006
    6.4
    Medium

    CVE-2006-2149

    Last Modified: 20 Jul 2016

    PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via the CONFIG[path] parameter, as demonstrated by including a GIF that contains PHP code.

    Source:cijfer
    Published:3 May 2006
    6.4
    Medium

    CVE-2006-2144

    Last Modified: 23 Aug 2013

    PHP remote file inclusion vulnerability in kopf.php in DMCounter 0.9.2-b allows remote attackers to execute arbitrary PHP code via a URL in the rootdir parameter.

    Source:beford
    Published:2 May 2006
    4.3
    Medium

    CVE-2006-2143

    Last Modified: 22 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in TextFileBB 1.0.16 allow remote attackers to inject arbitrary web script or HTML via Javascript events such as "onmouseover" in the (1) color, (2) size, or (3) url bbcode tags.

    Source:r0xes
    Published:2 May 2006
    6.4
    Medium

    CVE-2006-2142

    Last Modified: 10 Nov 2016

    PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the classes_dir parameter.

    Source:[Oo]
    Published:2 May 2006
    4.3
    Medium

    CVE-2006-2141

    Last Modified: 23 Aug 2013

    Cross-site scripting (XSS) vulnerability in popup_image in Collaborative Portal Server (CPS) 3.4.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the pos argument.

    Source:r0t
    Published:2 May 2006
    5.8
    Medium

    CVE-2006-2140

    Last Modified: 23 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in OrbitHYIP 2.0 and earlier allow remote attackers to inject arbitrary web script via the (1) referral parameter to signup.php or (2) id parameter to members.php.

    Source:r0t
    Published:2 May 2006
    4.3
    Medium

    CVE-2006-2138

    Last Modified: 22 Aug 2013

    Cross-site scripting (XSS) vulnerability in neomail.pl in NeoMail 1.29 allows remote attackers to inject arbitrary web script or HTML via the sessionid parameter.

    Source:O.U.T.L.A.W
    Published:2 May 2006
    7.5
    High

    CVE-2006-2137

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in master.php in OpenPHPNuke and 2.3.3 earlier allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter.

    Source:[Oo]
    Published:2 May 2006
    5.1
    Medium

    CVE-2006-2134

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the module_root_path parameter.

    Source:[Oo]
    Published:2 May 2006
    6.4
    Medium

    CVE-2006-2132

    Last Modified: 22 Aug 2013

    SQL injection vulnerability in detail.asp in DUclassified allows remote attackers to execute arbitrary SQL commands via the iPro parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:sadegh.sarshogh
    Published:1 May 2006
    6.4
    Medium

    CVE-2006-2127

    Last Modified: 22 Aug 2013

    SQL injection vulnerability in weblog_posting.php in Blog Mod 0.2.x allows remote attackers to execute arbitrary SQL commands via the r parameter.

    Source:Qex
    Published:1 May 2006
    6.4
    Medium

    CVE-2006-2126

    Last Modified: 23 Aug 2013

    SQL injection vulnerability in pocategories.php in MaxTrade 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) categori and (2) stranica parameters.

    Source:r0t
    Published:1 May 2006
    5.8
    Medium

    CVE-2006-2124

    Last Modified: 23 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SunShop 3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) prevaction, (2) previd, (3) prevstart, (4) itemid, (5) id, and (6) action parameters in index.php.

    Source:r0t
    Published:1 May 2006
    6.8
    Medium

    CVE-2006-2122

    Last Modified: 22 Aug 2013

    PHP remote file inclusion vulnerability in index.php in CoolMenus allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: the original report for this issue is probably erroneous, since CoolMenus does not appear to be written in PHP.

    Source:botan
    Published:1 May 2006
    5
    Medium

    CVE-2006-2121

    Last Modified: 22 Aug 2013

    PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL in the include_path parameter. NOTE: this is a different vector, and possibly a different vulnerability, than CVE-2006-1929.

    Source:O.U.T.L.A.W
    Published:1 May 2006
    5
    Medium

    CVE-2006-2119

    Last Modified: 22 Aug 2013

    PHP remote file inclusion vulnerability in event/index.php in Artmedic Event allows remote attackers to execute arbitrary code via a URL in the page parameter.

    Source:botan
    Published:1 May 2006
    7.5
    High

    CVE-2006-2116

    Last Modified: 22 Aug 2013

    planetGallery allows remote attackers to gain administrator privileges via a direct request to admin/gallery_admin.php.

    Source:tugr@
    Published:1 May 2006
    4.3
    Medium

    CVE-2006-2111

    Last Modified: 27 Aug 2013

    A component in Microsoft Outlook Express 6 allows remote attackers to bypass domain restrictions and obtain sensitive information via redirections with the mhtml: URI handler, as originally reported for Internet Explorer 6 and 7, aka "URL Redirect Cross Domain Information Disclosure Vulnerability."

    Source:codedreamer
    Published:1 May 2006
    6.8
    Medium

    CVE-2006-2109

    Last Modified: 23 Aug 2013

    Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using the table parameter to login.php.

    Source:Alexander Klink
    Published:2 May 2006
    7.8
    High

    CVE-2006-2108

    Last Modified: 16 Apr 2026

    parser.exe in Océ (OCE) 3121/3122 Printer allows remote attackers to cause a denial of service (crash or reboot) via a long request, possibly triggering a buffer overflow.

    Source:sh4d0wman
    Published:29 Apr 2006
    7.5
    High

    CVE-2006-2107

    Last Modified: 16 Apr 2026

    Buffer overflow in BL4 SMTP Server 0.1.4 and earlier allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long argument to the (1) EHLO, (2) MAIL FROM, and (3) RCPT TO commands.

    Source:Dedi Dwianto
    Published:29 Apr 2006
    7.8
    High

    CVE-2006-2102

    Last Modified: 27 Aug 2013

    Directory traversal vulnerability in PowerISO 2.9 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

    Source:Sowhat
    Published:29 Apr 2006
    5
    Medium

    CVE-2006-2101

    Last Modified: 27 Aug 2013

    Directory traversal vulnerability in WinISO 5.3 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

    Source:Sowhat
    Published:29 Apr 2006
    7.8
    High

    CVE-2006-2100

    Last Modified: 27 Aug 2013

    Directory traversal vulnerability in Magic ISO 5.0 Build 0166 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

    Source:Sowhat
    Published:29 Apr 2006
    5
    Medium

    CVE-2006-2099

    Last Modified: 27 Aug 2013

    Directory traversal vulnerability in UltraISO 8.0.0.1392 allows remote attackers to write arbitrary files via a .. (dot dot) in a filename in an ISO image.

    Source:Sowhat
    Published:29 Apr 2006
    7.5
    High

    CVE-2006-2097

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in func_msg.php in Invision Power Board (IPB) 2.1.4 allows remote attackers to execute arbitrary SQL commands via the from_contact field in a private message (PM).

    Source:Ykstortion Security
    Published:29 Apr 2006
    5.1
    Medium

    CVE-2006-2094

    Last Modified: 21 Aug 2013

    Microsoft Internet Explorer before Windows XP Service Pack 2 and Windows Server 2003 Service Pack 1, when Prompt is configured in Security Settings, uses modal dialogs to verify that a user wishes to run an ActiveX control or perform other risky actions, which allows user-assisted remote attackers to construct a race condition that tricks a user into clicking an object or pressing keys that are actually applied to a "Yes" approval for executing the control.

    Source:Matthew Murphy
    Published:29 Apr 2006
    4.3
    Medium

    CVE-2006-2089

    Last Modified: 21 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in misc.php in MySmartBB 1.1.x allow remote attackers to inject arbitrary web script or HTML via the (1) id and (2) username parameters.

    Source:BoNy-m
    Published:29 Apr 2006
    7.5
    High

    CVE-2006-2086

    Last Modified: 10 Mar 2011

    Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, allows remote attackers to execute arbitrary code via a long argument in the ProductName parameter.

    Source:Metasploit
    Published:29 Apr 2006
    4.6
    Medium

    CVE-2006-2081

    Last Modified: 16 Apr 2026

    Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via the GET_DOMAIN_INDEX_METADATA function in the DBMS_EXPORT_EXTENSION package. NOTE: this issue was originally linked to DB05 (CVE-2006-1870), but a reliable third party has claimed that it is not the same issue. Based on details of the problem, the primary issue appears to be insecure privileges that facilitate the introduction of SQL in a way that is not related to special characters, so this is not "SQL injection" per se.

    Source:N1V1Hd
    Published:27 Apr 2006
    4.3
    Medium

    CVE-2006-2079

    Last Modified: 21 Aug 2013

    Cross-site scripting (XSS) vulnerability in portfolio.php in Verosky Media Instant Photo Gallery, possibly before 1.0.2, allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter.

    Source:Qex
    Published:27 Apr 2006
    4.3
    Medium

    CVE-2006-2070

    Last Modified: 21 Aug 2013

    Cross-site scripting (XSS) vulnerability in member.php in DevBB 1.0.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action.

    Source:Qex
    Published:27 Apr 2006
    7.5
    High

    CVE-2006-2067

    Last Modified: 20 Aug 2013

    SQL injection vulnerability in vb_board_functions.php in MKPortal 1.1, as used with vBulletin 3.5.4 and earlier, allows remote attackers to execute arbitrary SQL commands via the userid parameter.

    Source:Mustafa Can Bjorn IPEKCI
    Published:27 Apr 2006
    4.3
    Medium

    CVE-2006-2066

    Last Modified: 4 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.

    Source:HanowarS
    Published:27 Apr 2006
    7.5
    High

    CVE-2006-2065

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in save.php in PHPSurveyor 0.995 and earlier allows remote attackers to execute arbitrary SQL commands via the surveyid cookie. NOTE: this issue could be leveraged to execute arbitrary PHP code, as demonstrated by inserting directory traversal sequences into the database, which are then processed by the thissurvey['language'] variable.

    Source:rgod
    Published:27 Apr 2006