5
    Medium

    CVE-2006-2061

    Last Modified: 21 Aug 2013

    SQL injection vulnerability in lib/func_taskmanager.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary SQL commands via the ck parameter, which can inject at most 32 characters.

    Source:IceShaman
    Published:26 Apr 2006
    5
    Medium

    CVE-2006-2059

    Last Modified: 16 Apr 2026

    action_public/search.php in Invision Power Board (IPB) 2.1.x and 2.0.x before 20060425 allows remote attackers to execute arbitrary PHP code via a search with a crafted value of the lastdate parameter, which alters the behavior of a regular expression to add a "#e" (execute) modifier.

    Source:RusH
    Published:26 Apr 2006
    5.8
    Medium

    CVE-2006-2052

    Last Modified: 21 Aug 2013

    Cross-site scripting (XSS) vulnerability in Verosky Media Instant Photo Gallery allows remote attackers to inject arbitrary web script or HTML via the member parameter in a viewpro action in member.php. NOTE: the original report may be inaccurate, since the "viewpro" string does not appear in the source code for version 1.0.2 of the product.

    Source:Qex
    Published:26 Apr 2006
    5.8
    Medium

    CVE-2006-2051

    Last Modified: 21 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in myadmin/index.php in NextAge Shopping Cart allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) password parameters.

    Source:R@1D3N
    Published:26 Apr 2006
    4.3
    Medium

    CVE-2006-2048

    Last Modified: 21 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Edwin van Wijk phpWebFTP 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) port, (2) server, and (3) user parameters. NOTE: it is possible that the affected version is actually 3.2.

    Source:arko.dhar
    Published:26 Apr 2006
    6.4
    Medium

    CVE-2006-2046

    Last Modified: 6 Dec 2016

    Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.

    Source:r0t
    Published:26 Apr 2006
    4.6
    Medium

    CVE-2006-2043

    Last Modified: 16 Apr 2026

    na-img-4.0.34.bin for the IP3 Networks NetAccess NA75 allows local users to gain Unix shell access via "`" (backtick) characters in the appliance's command line interface (CLI).

    Source:r00t
    Published:26 Apr 2006
    6.4
    Medium

    CVE-2006-2040

    Last Modified: 21 Nov 2016

    Multiple SQL injection vulnerabilities in photokorn 1.53 and 1.542 allow remote attackers to execute arbitrary SQL commands via the (1) cat, (2) pic and (3) page parameter in index.php; (4) id parameter in postcard.php; and (5) cat parameter in print.php.

    Source:Dr.Jr7
    Published:26 Apr 2006
    4.3
    Medium

    CVE-2006-2037

    Last Modified: 20 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in Thwboard 3.0 Beta 2.84 allows remote attackers to inject arbitrary web script or HTML via the navpath parameter.

    Source:CrAzY CrAcKeR
    Published:26 Apr 2006
    7.5
    High

    CVE-2006-2034

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in function/showprofile.php in FlexBB 0.5.5 allows remote attackers to execute arbitrary SQL commands, and view all usernames and passwords, via the id parameter to the showprofile page in index.php.

    Source:Devil-00
    Published:26 Apr 2006
    6.4
    Medium

    CVE-2006-2032

    Last Modified: 8 Dec 2016

    Multiple SQL injection vulnerabilities in Core CoreNews 2.0.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) icon_id and (2) userid parameters in preview.php.

    Source:nukedx
    Published:26 Apr 2006
    6.4
    Medium

    CVE-2006-2029

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) tid parameter in (a) preview.php; the (2) cid, (3) pid, and (4) eid parameters in (b) archive.php; and the (5) pid parameter in (c) comments.php.

    Source:rgod
    Published:26 Apr 2006
    5.8
    Medium

    CVE-2006-2028

    Last Modified: 20 Aug 2013

    Cross-site scripting (XSS) vulnerability in imagelist.php in Jeremy Ashcraft Simplog 0.9.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the imagedir parameter. NOTE: this issue might be resultant from directory traversal.

    Source:nukedx
    Published:26 Apr 2006
    6.5
    Medium

    CVE-2006-2027

    Last Modified: 16 Apr 2026

    Buffer overflow in Unicode processing in the logging functionality in Pablo Software Solutions Quick 'n Easy FTP Server Professional and Lite, probably 3.0, allows remote authenticated users to execute arbitrary code by sending a command with a long argument, which triggers a buffer overflow when an admin selects the Logging section in the FTP server main window. NOTE: the original researcher claims that the vendor disputes this issue.

    Source:KaGra
    Published:26 Apr 2006
    6.5
    Medium

    CVE-2006-2026

    Last Modified: 27 Aug 2013

    Double free vulnerability in tif_jpeg.c in libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted TIFF image that triggers errors related to "setfield/getfield methods in cleanup functions."

    Source:Tavis Ormandy
    Published:3 Mar 2006
    6.5
    Medium

    CVE-2006-2025

    Last Modified: 27 Aug 2013

    Integer overflow in the TIFFFetchData function in tif_dirread.c for libtiff before 3.8.1 allows context-dependent attackers to cause a denial of service and possibly execute arbitrary code via a crafted TIFF image.

    Source:Tavis Ormandy
    Published:3 Mar 2006
    4
    Medium

    CVE-2006-2024

    Last Modified: 27 Aug 2013

    Multiple vulnerabilities in libtiff before 3.8.1 allow context-dependent attackers to cause a denial of service via a TIFF image that triggers errors in (1) the TIFFFetchAnyArray function in (a) tif_dirread.c; (2) certain "codec cleanup methods" in (b) tif_lzw.c, (c) tif_pixarlog.c, and (d) tif_zip.c; (3) and improper restoration of setfield and getfield methods in cleanup functions within (e) tif_jpeg.c, tif_pixarlog.c, (f) tif_fax3.c, and tif_zip.c.

    Source:Tavis Ormandy
    Published:3 Mar 2006
    7.5
    High

    CVE-2006-2022

    Last Modified: 29 Sept 2016

    Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote attackers to execute arbitrary code via a long URL.

    Source:c0d3r
    Published:25 Apr 2006
    7.8
    High

    CVE-2006-2020

    Last Modified: 20 Aug 2013

    Asterisk Recording Interface (ARI) in Asterisk@Home before 2.8 stores recordings/includes/main.conf under the web document root with insufficient access control, which allows remote attackers to obtain password information.

    Source:Francois Harvey
    Published:25 Apr 2006
    5
    Medium

    CVE-2006-2019

    Last Modified: 20 Jul 2016

    Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CPU consumption and crash) via a TD element with a large number in the rowspan attribute.

    Source:Yannick von Arx
    Published:25 Apr 2006
    2.6
    Low

    CVE-2006-2016

    Last Modified: 6 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in phpLDAPadmin 0.9.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dn parameter in (a) compare_form.php, (b) copy_form.php, (c) rename_form.php, (d) template_engine.php, and (e) delete_form.php; (2) scope parameter in (f) search.php; and (3) Container DN, (4) Machine Name, and (5) UID Number fields in (g) template_engine.php.

    Source:r0t
    Published:25 Apr 2006
    5
    Medium

    CVE-2006-2012

    Last Modified: 20 Jul 2016

    Format string vulnerability in Skulltag 0.96f and earlier allows remote attackers to cause a denial of service via the version string.

    Source:Luigi Auriemma
    Published:25 Apr 2006
    7.5
    High

    CVE-2006-2008

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attackers to execute arbitrary PHP code via a URL in the full_path parameter.

    Source:Camille Myers
    Published:25 Apr 2006
    7.5
    High

    CVE-2006-2005

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in index.php in ClanSys 1.1 allows remote attackers to execute arbitrary PHP code via PHP code in the page parameter, as demonstrated by using an "include" statement that is injected into the eval statement. NOTE: this issue has been described as file inclusion by some sources, but that is just one attack; the primary vulnerability is eval injection.

    Source:nukedx
    Published:25 Apr 2006
    5
    Medium

    CVE-2006-2002

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in stats.php in MyGamingLadder 7.0 allows remote attackers to execute arbitrary PHP code via a URL in the dir[base] parameter.

    Source:nukedx
    Published:25 Apr 2006
    4.3
    Medium

    CVE-2006-2001

    Last Modified: 21 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this is a different vulnerability than the directory traversal vector.

    Source:mayank
    Published:25 Apr 2006
    5
    Medium

    CVE-2006-1999

    Last Modified: 20 Jul 2016

    The multiplayer menu in OpenTTD 0.4.7 allows remote attackers to cause a denial of service via a UDP packet with an incorrect size, which causes the client to return to the main menu.

    Source:Luigi Auriemma
    Published:25 Apr 2006
    2.1
    Low

    CVE-2006-1998

    Last Modified: 20 Jul 2016

    OpenTTD 0.4.7 and earlier allows local users to cause a denial of service (application exit) via a large invalid error number, which triggers an error.

    Source:Luigi Auriemma
    Published:25 Apr 2006
    5
    Medium

    CVE-2006-1995

    Last Modified: 20 Aug 2013

    Directory traversal vulnerability in index.php in Scry Gallery 1.1 allows remote attackers to read arbitrary files via ".." sequences in the p parameter, which is not properly sanitized due to an rtrim function call with the arguments in the wrong order.

    Source:Morocco Security Team
    Published:25 Apr 2006
    7.5
    High

    CVE-2006-1994

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php.

    Source:nukedx
    Published:25 Apr 2006
    5.1
    Medium

    CVE-2006-1993

    Last Modified: 16 Apr 2026

    Mozilla Firefox 1.5.0.2, when designMode is enabled, allows remote attackers to cause a denial of service and possibly execute arbitrary code via certain Javascript that is not properly handled by the contentWindow.focus method in an iframe, which causes a reference to a deleted controller context object. NOTE: this was originally claimed to be a buffer overflow in (1) js320.dll and (2) xpcom_core.dll, but the vendor disputes this claim.

    Source:splices
    Published:25 Apr 2006
    2.6
    Low

    CVE-2006-1992

    Last Modified: 21 Aug 2013

    mshtml.dll 6.00.2900.2873, as used in Microsoft Internet Explorer, allows remote attackers to cause a denial of service (crash) via nested OBJECT tags, which trigger invalid pointer dereferences including NULL dereferences. NOTE: the possibility of code execution was originally theorized, but Microsoft has stated that this issue is non-exploitable.

    Source:Michal Zalewski
    Published:25 Apr 2006
    5.1
    Medium

    CVE-2006-1985

    Last Modified: 27 Aug 2013

    Heap-based buffer overflow in BOM BOMArchiveHelper 10.4 (6.3) Build 312, as used in Mac OS X 10.4.6 and earlier, allows user-assisted attackers to execute arbitrary code via a crafted archive (such as ZIP) that contains long path names, which triggers an error in the BOMStackPop function.

    Source:Tom Ferris
    Published:21 Apr 2006
    7.5
    High

    CVE-2006-1982

    Last Modified: 27 Aug 2013

    Heap-based buffer overflow in the LZWDecodeVector function in Mac OS X before 10.4.6, as used in applications that use ImageIO or AppKit, allows remote attackers to execute arbitrary code via crafted TIFF images.

    Source:Tom Ferris
    Published:21 Apr 2006
    2.6
    Low

    CVE-2006-1980

    Last Modified: 20 Aug 2013

    Cross-site scripting (XSS) vulnerability in W2B Online Banking allows remote attackers to inject arbitrary web script or HTML via the (1) query string, (2) SID parameter, or (3) ilang parameter.

    Source:r0t
    Published:21 Apr 2006
    5.8
    Medium

    CVE-2006-1979

    Last Modified: 20 Aug 2013

    Cross-site scripting (XSS) vulnerability in mwguest.php in Manic Web MWGuest 2.1.0 allows remote attackers to inject arbitrary web script or HTML via the homepage parameter.

    Source:Aliaksandr Hartsuyeu
    Published:21 Apr 2006
    7.5
    High

    CVE-2006-1978

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in inc/start.php in FlexBB 0.5.5 and earlier allows remote attackers to execute arbitrary SQL commands via the flexbb_username COOKIE parameter.

    Source:Devil-00
    Published:21 Apr 2006
    7.5
    High

    CVE-2006-1974

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitrary SQL commands via the referrer parameter.

    Source:Devil-00
    Published:21 Apr 2006
    4.3
    Medium

    CVE-2006-1971

    Last Modified: 19 Aug 2013

    Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.

    Source:botan
    Published:21 Apr 2006
    5.8
    Medium

    CVE-2006-1965

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in aasi media Net Clubs Pro 4.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) onuser, (2) pass, (3) chatsys, (4) room, (5) username, and (6) to parameters in (a) sendim.cgi; the (7) username parameter in (b) imessage.cgi; the (8) password parameter in (c) login.cgi; and the (9) cat_id parameter in (d) viewcat.cgi.

    Source:r0t
    Published:21 Apr 2006
    5.8
    Medium

    CVE-2006-1960

    Last Modified: 19 Aug 2013

    Cross-site scripting (XSS) vulnerability in the appliance web user interface in Cisco CiscoWorks Wireless LAN Solution Engine (WLSE) and WLSE Express before 2.13 allows remote attackers to inject arbitrary web script or HTML, possibly via the displayMsg parameter to archiveApplyDisplay.jsp, aka bug ID CSCsc01095.

    Source:Adam Pointon
    Published:21 Apr 2006
    7.5
    High

    CVE-2006-1959

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in direct.php in ActualScripts ActualAnalyzer Lite 2.72 and earlier, Gold 7.63 and earlier, and Server 8.23 and earlier allows remote attackers to execute arbitrary code via a URL in the rf parameter.

    Source:Aesthetico
    Published:21 Apr 2006
    5
    Medium

    CVE-2006-1954

    Last Modified: 20 Oct 2017

    SQL injection vulnerability in authent.php4 in Nicolas Fischer (aka NFec) RechnungsZentrale V2 1.1.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the User field.

    Source:GroundZero Security
    Published:21 Apr 2006
    4.3
    Medium

    CVE-2006-1950

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in banners.cgi in PerlCoders BannerFarm 2.3 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) aff and (2) cat parameters.

    Source:r0t
    Published:20 Apr 2006
    7.5
    High

    CVE-2006-1947

    Last Modified: 19 Aug 2013

    Multiple SQL injection vulnerabilities in plexum.php in NicPlex Plexum X5 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) pagesize, (2) maxrec, and (3) startpos parameters.

    Source:r0t
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1946

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Visale 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the keyval parameter in pbpgst.cgi, (2) the catsubno parameter in pblscg.cgi, and (3) the listno parameter in pblsmb.cgi.

    Source:r0t
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1945

    Last Modified: 19 Aug 2013

    Cross-site scripting (XSS) vulnerability in awstats.pl in AWStats 6.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the config parameter. NOTE: this might be the same core issue as CVE-2005-2732.

    Source:r0t
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1944

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in SibSoft CommuniMail 1.2 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the list_id parameter in mailadmin.cgi and (2) the form_id parameter in templates.cgi.

    Source:r0t
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1943

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Smarter Scripts IntelliLink Pro 5.06 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) url parameter in addlink_lwp.cgi and the (2) id, (3) forgotid, and (4) forgotpass parameters in edit.cgi.

    Source:r0t
    Published:20 Apr 2006
    5
    Medium

    CVE-2006-1941

    Last Modified: 18 Aug 2013

    Neon Responder 5.4 for LANsurveyor allows remote attackers to cause a denial of service (application outage) via a crafted Clock Synchronisation packet that triggers an access violation.

    Source:Stefan Lochbihler
    Published:20 Apr 2006