5
    Medium

    CVE-2006-1931

    Last Modified: 20 Aug 2013

    The HTTP/XMLRPC server in Ruby before 1.8.2 uses blocking sockets, which allows attackers to cause a denial of service (blocked connections) via a large amount of data.

    Source:Tanaka Akira
    Published:30 Jun 2005
    5
    Medium

    CVE-2006-1929

    Last Modified: 20 Aug 2013

    PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.

    Source:r0t
    Published:20 Apr 2006
    5
    Medium

    CVE-2006-1926

    Last Modified: 19 Aug 2013

    SQL injection vulnerability in showtopic.php in ThWboard 2.84 beta 3 and earlier allows remote attackers to execute arbitrary SQL commands via the pagenum parameter.

    Source:Qex
    Published:20 Apr 2006
    4.3
    Medium

    CVE-2006-1925

    Last Modified: 18 Aug 2013

    Directory traversal vulnerability in the editnews module (inc/editnews.mdu) in index.php in CuteNews 1.4.1 allows remote attackers to read or modify files via the source parameter in the (1) editnews or (2) doeditnews action. NOTE: this can also produce resultant XSS when the target file does not exist.

    Source:LoK-Crew
    Published:20 Apr 2006
    6.4
    Medium

    CVE-2006-1922

    Last Modified: 19 Aug 2013

    PHP remote file inclusion vulnerability in (1) about.php or (2) auth.php in TotalCalendar allows remote attackers to execute arbitrary PHP code via a URL in the inc_dir parameter.

    Source:VietMafia
    Published:20 Apr 2006
    6.4
    Medium

    CVE-2006-1921

    Last Modified: 16 Apr 2026

    nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the host parameter.

    Source:FOX_MULDER
    Published:20 Apr 2006
    7.5
    High

    CVE-2006-1919

    Last Modified: 29 Nov 2016

    PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitrary PHP code via a URL in the page parameter.

    Source:Hessam-x
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1918

    Last Modified: 17 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Papoo 2.1.5 allow remote attackers to inject arbitrary web script or HTML via the menuid parameter to (1) index.php or (2) forum.php, or the (3) reporeid_print parameter to print.php.

    Source:Rusydi Hasan
    Published:20 Apr 2006
    7.5
    High

    CVE-2006-1917

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitrary SQL commands via the userID parameter.

    Source:snatcher
    Published:20 Apr 2006
    6.8
    Medium

    CVE-2006-1916

    Last Modified: 18 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in profile.php in DbbS 2.0-alpha and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) ulocation or (2) uhobbies parameters.

    Source:rgod
    Published:20 Apr 2006
    6.8
    Medium

    CVE-2006-1913

    Last Modified: 18 Aug 2013

    Cross-site scripting (XSS) vulnerability in jax_guestbook.php in Jax Guestbook 3.1, 3.31, and 3.50 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:ALMOKANN3
    Published:20 Apr 2006
    5.8
    Medium

    CVE-2006-1912

    Last Modified: 18 Aug 2013

    MyBB (MyBulletinBoard) 1.1.0 does not set the constant KILL_GLOBAL variable in (1) global.php and (2) inc/init.php, which allows remote attackers to initialize arbitrary variables that are processed by an @extract command, which could then be leveraged to conduct cross-site scripting (XSS) or SQL injection attacks.

    Source:imei
    Published:20 Apr 2006
    5
    Medium

    CVE-2006-1909

    Last Modified: 18 Aug 2013

    Directory traversal vulnerability in index.php in Coppermine 1.4.4 allows remote attackers to read arbitrary files via a .//./ (modified dot dot slash) in the file parameter, which causes a regular expression to collapse the sequences into standard "../" sequences.

    Source:imei
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1906

    Last Modified: 18 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in jjgan852 phpLister 0.4.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:botan
    Published:20 Apr 2006
    7.5
    High

    CVE-2006-1905

    Last Modified: 18 Aug 2013

    Multiple format string vulnerabilities in xiTK (xitk/main.c) in xine 0.99.3 allow remote attackers to execute arbitrary code via format string specifiers in a long filename on an EXTINFO line in a playlist file.

    Source:c0ntexb
    Published:20 Apr 2006
    7.6
    High

    CVE-2006-1900

    Last Modified: 17 Aug 2013

    Multiple buffer overflows in World Wide Web Consortium (W3C) Amaya 9.4, and possibly other versions including 8.x before 8.8.5, allow remote attackers to execute arbitrary code via a long value in (1) the COMPACT attribute of the COLGROUP element, (2) the ROWS attribute of the TEXTAREA element, and (3) the COLOR attribute of the LEGEND element; and via other unspecified attack vectors consisting of "dozens of possible snippets."

    Source:Thomas Waldegger
    Published:20 Apr 2006
    6.8
    Medium

    CVE-2006-1893

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in print.php in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:ALMOKANN3
    Published:20 Apr 2006
    2.6
    Low

    CVE-2006-1878

    Last Modified: 18 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in phpFaber TopSites allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:botan
    Published:20 Apr 2006
    4.6
    Medium

    CVE-2006-1864

    Last Modified: 22 Aug 2013

    Directory traversal vulnerability in smbfs in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1863.

    Source:Marcel Holtmann
    Published:26 Apr 2006
    2.1
    Low

    CVE-2006-1863

    Last Modified: 22 Aug 2013

    Directory traversal vulnerability in CIFS in Linux 2.6.16 and earlier allows local users to escape chroot restrictions for an SMB-mounted filesystem via "..\\" sequences, a similar vulnerability to CVE-2006-1864.

    Source:Marcel Holtmann
    Published:20 Apr 2006
    6.5
    Medium

    CVE-2006-1853

    Last Modified: 19 Aug 2013

    Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.

    Source:r0t
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1852

    Last Modified: 18 Aug 2013

    SQL injection vulnerability in category.php in Article Publisher Pro 1.0.1 and earlier allows remote attackers to execute arbitrary SQL commands via the cname parameter.

    Source:r0t
    Published:19 Apr 2006
    2.6
    Low

    CVE-2006-1850

    Last Modified: 19 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in xFlow 5.46.11 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) level, (2) position, (3) id, and (4) action parameters to members_only/index.cgi, and the (5) page parameter to customer_area/index.cgi.

    Source:r0t
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1849

    Last Modified: 19 Aug 2013

    Multiple SQL injection vulnerabilities in members_only/index.cgi in xFlow 5.46.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) position and (2) id parameter.

    Source:r0t
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1839

    Last Modified: 17 Aug 2013

    PHP remote file inclusion vulnerability in language.php in PHP Album 0.3.2.3, when register_globals is enabled, allows remote attackers to execute arbitrary code via an FTP URL in the data_dir parameter, which satisfies the file_exists function call.

    Source:rgod
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1838

    Last Modified: 16 Apr 2026

    edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.

    Source:snatcher
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1837

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter.

    Source:snatcher
    Published:19 Apr 2006
    2.6
    Low

    CVE-2006-1835

    Last Modified: 18 Aug 2013

    Cross-site scripting (XSS) vulnerability in yearcal.php in Calendarix allows remote attackers to inject arbitrary web script or HTML via the ycyear parameter.

    Source:botan
    Published:19 Apr 2006
    5.1
    Medium

    CVE-2006-1834

    Last Modified: 17 Aug 2013

    Integer signedness error in Opera before 8.54 allows remote attackers to execute arbitrary code via long values in a stylesheet attribute, which pass a length check. NOTE: a sign extension problem makes the attack easier with shorter strings.

    Source:SEC Consult
    Published:19 Apr 2006
    5
    Medium

    CVE-2006-1832

    Last Modified: 16 Apr 2026

    sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.

    Source:rgod
    Published:19 Apr 2006
    7.5
    High

    CVE-2006-1831

    Last Modified: 16 Apr 2026

    Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows remote attackers to execute arbitrary commands via a leading ; (semicolon) in the name parameter in a systemdoc action, which is injected into phpinfo.php.

    Source:rgod
    Published:19 Apr 2006
    5.1
    Medium

    CVE-2006-1828

    Last Modified: 7 Jul 2016

    SQL injection vulnerability in php121language.php in PHP121 1.4 allows remote attackers to execute arbitrary SQL commands and execute arbitrary code via the sess_username variable, as set by the php121un HTTP COOKIE parameter, which is used in multiple files including php121login.php. NOTE: the code execution occurs because the SQL query results are used in an include statement.

    Source:rgod
    Published:19 Apr 2006
    6.8
    Medium

    CVE-2006-1825

    Last Modified: 18 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in phpLinks 2.1.3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the term parameter.

    Source:r0t
    Published:18 Apr 2006
    5.8
    Medium

    CVE-2006-1822

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in search.php in FarsiNews 2.5.3 Pro and earlier allows remote attackers to inject arbitrary web script or HTML via the selected_search_arch parameter.

    Source:amin emami
    Published:18 Apr 2006
    6.4
    Medium

    CVE-2006-1821

    Last Modified: 17 Aug 2013

    Directory traversal vulnerability in index.php in ModX 0.9.1 allows remote attackers to read arbitrary files via a .. (dot dot) sequence and trailing NULL (%00) byte in the id parameter.

    Source:Rusydi Hasan
    Published:18 Apr 2006
    5.8
    Medium

    CVE-2006-1820

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in ModX 0.9.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter. NOTE: this might be resultant from the directory traversal vulnerability.

    Source:Rusydi Hasan
    Published:18 Apr 2006
    2.6
    Low

    CVE-2006-1808

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in Lifetype 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the show parameter in a Template operation.

    Source:Rusydi Hasan
    Published:18 Apr 2006
    7.5
    High

    CVE-2006-1805

    Last Modified: 23 Jan 2017

    SQL injection vulnerability in member.php in PowerClan 1.14 allows remote attackers to execute arbitrary SQL commands via the memberid parameter.

    Source:d4igoro
    Published:18 Apr 2006
    4.3
    Medium

    CVE-2006-1803

    Last Modified: 16 Aug 2013

    Cross-site scripting (XSS) vulnerability in sql.php in phpMyAdmin 2.7.0-pl1 allows remote attackers to inject arbitrary web script or HTML via the sql_query parameter.

    Source:p0w3r
    Published:18 Apr 2006
    4.3
    Medium

    CVE-2006-1802

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in TinyWebGallery 1.3 and 1.4 allows remote attackers to inject arbitrary web script or HTML via the twg_album parameter.

    Source:Qex
    Published:18 Apr 2006
    4.3
    Medium

    CVE-2006-1801

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in planetsearchplus.php in planetSearch+ allows remote attackers to inject arbitrary web script or HTML via the search_exp parameter.

    Source:d4igoro
    Published:18 Apr 2006
    7.5
    High

    CVE-2006-1800

    Last Modified: 17 Aug 2013

    Directory traversal vulnerability in posts.php in SimpleBBS 1.0.6 through 1.1 allows remote attackers to include and execute arbitrary files via ".." sequences in the language cookie, as demonstrated by by injecting the code into the gl_session cookie of users.php, which is stored in error.log.

    Source:rUnViRuS
    Published:18 Apr 2006
    7.5
    High

    CVE-2006-1799

    Last Modified: 16 Apr 2026

    censtore.cgi in Censtore 7.3.002 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the page parameter.

    Source:FOX_MULDER
    Published:18 Apr 2006
    7.6
    High

    CVE-2006-1794

    Last Modified: 19 Jan 2018

    SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arbitrary SQL commands via (1) the $username variable in the mosGetParam function and (2) the $task parameter in the mosMenuCheck function in (a) includes/mambo.php; and (3) the $filter variable to the showCategory function in the com_content component (content.php).

    Source:GulfTech Security
    Published:17 Apr 2006
    7.6
    High

    CVE-2006-1793

    Last Modified: 28 Nov 2016

    Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPath[path] parameter to (1) class.forumposts.php and (2) forumpollrenderer.php. NOTE: this issue is closely related to CVE-2006-0659.

    Source:rgod
    Published:17 Apr 2006
    2.6
    Low

    CVE-2006-1786

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in Adobe Document Server for Reader Extensions 6.0 allows remote attackers to inject arbitrary web script or HTML via (1) the actionID parameter in ads-readerext and (2) the op parameter in AlterCast. NOTE: it is not clear whether the vendor advisory addresses this issue.

    Source:Tan Chew Keong
    Published:13 Apr 2006
    5.1
    Medium

    CVE-2006-1784

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the settings_dir parameter.

    Source:rgod
    Published:13 Apr 2006
    2.6
    Low

    CVE-2006-1783

    Last Modified: 17 Aug 2013

    Cross-site scripting (XSS) vulnerability in PatroNet CMS allows remote attackers to inject arbitrary web script or HTML via the URI.

    Source:Soothackers
    Published:13 Apr 2006
    7.5
    High

    CVE-2006-1781

    Last Modified: 18 Aug 2013

    PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the root_path parameter. NOTE: It was later reported that 1.4.2 and earlier are affected.

    Source:r0t
    Published:13 Apr 2006
    6.8
    Medium

    CVE-2006-1779

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the btag parameter.

    Source:rgod
    Published:13 Apr 2006