7.5
    High

    CVE-2006-1618

    Last Modified: 14 Aug 2013

    Format string vulnerability in the (1) Con_message and (2) conPrintf functions in con_main.c in Doomsday engine 1.8.6 allows remote attackers to execute arbitrary code via format string specifiers in an argument to the JOIN command, and possibly other command arguments.

    Source:Luigi Auriemma
    Published:5 Apr 2006
    5
    Medium

    CVE-2006-1613

    Last Modified: 13 Aug 2013

    Multiple SQL injection vulnerabilities in aWebNews 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) user123 variable in (a) login.php or (b) fpass.php; or (2) cid parameter to (c) visview.php.

    Source:Aliaksandr Hartsuyeu
    Published:4 Apr 2006
    5.1
    Medium

    CVE-2006-1610

    Last Modified: 16 Apr 2026

    PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Autonomous LAN party (ALP), allows remote attackers to execute arbitrary PHP code via a URL in the libpath parameter. NOTE: this only occurs when register_globals is disabled.

    Source:uid0
    Published:4 Apr 2006
    2.1
    Low

    CVE-2006-1608

    Last Modified: 15 Aug 2013

    The copy function in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass safe mode and read arbitrary files via a source argument containing a compress.zlib:// URI.

    Source:Maksymilian Arciemowicz
    Published:10 Apr 2006
    4.3
    Medium

    CVE-2006-1595

    Last Modified: 13 Aug 2013

    Cross-site scripting (XSS) vulnerability in document/rqmkhtml.php in Claroline 1.7.4 and earlier allows remote attackers to read arbitrary files via ".." sequences in the file parameter in a rqEditHtml command.

    Source:rgod
    Published:3 Apr 2006
    5
    Medium

    CVE-2006-1593

    Last Modified: 23 Aug 2013

    The (1) ZD_MissingPlayer, (2) ZD_UseItem, and (3) ZD_LoadNewClientLevel functions in sv_main.cpp for (a) Zdaemon 1.08.01 and (b) X-Doom allows remote attackers to cause a denial of service (crash) via an invalid player slot or item number, which causes an invalid memory access, possibly due to an invalid array index.

    Source:Luigi Auriemma
    Published:3 Apr 2006
    4.3
    Medium

    CVE-2006-1590

    Last Modified: 14 Aug 2013

    Cross-site scripting (XSS) vulnerability in the PrintFreshPage function in (1) Basic Analysis and Security Engine (BASE) 1.2.4 and (2) Analysis Console for Intrusion Databases (ACID) 0.9.6b23 allows remote attackers to inject arbitrary web script or HTML via the (a) back parameter to base_graph_main.php, (b) netmask parameter to base_stat_ipaddr.php, or (c) submit parameter to base_qry_alert.php within BASE, or (d) query string to acid_main.php in ACID, which causes the request URI ($_SERVER['REQUEST_URI']) to be inserted into a refresh operation.

    Source:Adam Ely
    Published:3 Apr 2006
    7.5
    High

    CVE-2006-1586

    Last Modified: 13 Aug 2013

    SQL injection vulnerability in admin_login.asp in ISP of Egypt SiteMan allows remote attackers to execute arbitrary SQL commands via the pass parameter.

    Source:s3rv3r_hack3r
    Published:2 Apr 2006
    6.4
    Medium

    CVE-2006-1584

    Last Modified: 12 Aug 2013

    Unspecified vulnerability in index.php in Warcraft III Replay Parser for PHP 1.8c allows remote attackers to inject arbitrary web script or HTML via the page parameter, possibly related to fopen function calls or file uploads. NOTE: post-disclosure analysis by CVE suggests that the "page" parameter is not used in this product, and "id" might be the affected parameter.

    Source:botan
    Published:2 Apr 2006
    5.8
    Medium

    CVE-2006-1582

    Last Modified: 13 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to inject arbitrary web script or HTML via the _path parameter. NOTE: this might be resultant from the directory traversal issue.

    Source:Amine ABOUD
    Published:2 Apr 2006
    6.4
    Medium

    CVE-2006-1581

    Last Modified: 13 Aug 2013

    Directory traversal vulnerability in index.php in Blank'N'Berg 0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the _path parameter.

    Source:Amine ABOUD
    Published:2 Apr 2006
    5.8
    Medium

    CVE-2006-1580

    Last Modified: 13 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.

    Source:r0t
    Published:2 Apr 2006
    7.5
    High

    CVE-2006-1579

    Last Modified: 13 Aug 2013

    SQL injection vulnerability in topics.php in Dynamic Bulletin Board System (DbbS) 2.0-alpha and earlier allows remote attackers to execute arbitrary SQL commands via the limite parameter.

    Source:DaBDouB-MoSiKaR
    Published:2 Apr 2006
    7.5
    High

    CVE-2006-1573

    Last Modified: 12 Aug 2013

    PHP remote file inclusion vulnerability in index.php in MediaSlash Gallery allows remote attackers to execute arbitrary PHP code via a URL in the rub parameter (part of the $page_menu variable).

    Source:Morocco Security Team
    Published:1 Apr 2006
    5
    Medium

    CVE-2006-1572

    Last Modified: 8 Dec 2016

    SQL injection vulnerability in post.php in Oxygen 1.1.3 allows remote attackers to execute arbitrary SQL commands via the fid parameter in a newthread action.

    Source:Morocco Security Team
    Published:1 Apr 2006
    5.1
    Medium

    CVE-2006-1569

    Last Modified: 12 Aug 2013

    Multiple SQL injection vulnerabilities in RedCMS 0.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters to (a) login.php or (b) register.php; or (3) u parameter to (c) profile.php.

    Source:Aliaksandr Hartsuyeu
    Published:1 Apr 2006
    5.1
    Medium

    CVE-2006-1568

    Last Modified: 12 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in register.php in RedCMS 0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) email, (2) location, or (3) website parameters.

    Source:Aliaksandr Hartsuyeu
    Published:1 Apr 2006
    4.3
    Medium

    CVE-2006-1567

    Last Modified: 12 Aug 2013

    Cross-site scripting (XSS) vulnerability in searchresults.asp in SiteSearch Indexer 3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchField parameter.

    Source:r0t
    Published:1 Apr 2006
    7.5
    High

    CVE-2006-1557

    Last Modified: 12 Aug 2013

    Multiple SQL injection vulnerabilities in X-Changer 0.2 allow remote attackers to execute arbitrary SQL commands via the (1) from and (2) into parameters in a calculate action, and the (3) id parameter in an edit action to index.php.

    Source:Morocco Security Team
    Published:31 Mar 2006
    6.8
    Medium

    CVE-2006-1556

    Last Modified: 11 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in view_caricatier.php in AL-Caricatier 2.5 allow remote attackers to inject arbitrary web script or HTML via the (1) CatName, (2) CaricatierID, or (3) CatID parameter.

    Source:Linux_Drox
    Published:31 Mar 2006
    7.5
    High

    CVE-2006-1551

    Last Modified: 6 Mar 2011

    Eval injection vulnerability in pajax_call_dispatcher.php in PAJAX 0.5.1 and earlier allows remote attackers to execute arbitrary code via the (1) $method and (2) $args parameters.

    Source:Metasploit
    Published:13 Apr 2006
    2.1
    Low

    CVE-2006-1549

    Last Modified: 19 Nov 2013

    PHP 4.4.2 and 5.1.2 allows local users to cause a crash (segmentation fault) by defining and executing a recursive function. NOTE: it has been reported by a reliable third party that some later versions are also affected.

    Source:Maksymilian Arciemowicz
    Published:10 Apr 2006
    7.5
    High

    CVE-2006-1543

    Last Modified: 11 Aug 2013

    Multiple SQL injection vulnerabilities in vscripts (aka Kuba Kunkiewicz) VNews 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) loginvar parameter in (a) admin/admin.php, and the (2) news and (3) nom parameters in (b) news.php.

    Source:Aliaksandr Hartsuyeu
    Published:30 Mar 2006
    3.7
    Low

    CVE-2006-1542

    Last Modified: 30 Jun 2016

    Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allows local users to cause a "stack overflow," and possibly gain privileges, by running a script from a current working directory that has a long name, related to the realpath function. NOTE: this might not be a vulnerability. However, the fact that it appears in a programming language interpreter could mean that some applications are affected, although attack scenarios might be limited because the attacker might already need to cross privilege boundaries to cause an exploitable program to be placed in a directory with a long name; or, depending on the method that Python uses to determine the current working directory, setuid applications might be affected.

    Source:Gotfault Security
    Published:22 Sept 2005
    9.3
    Critical

    CVE-2006-1540

    Last Modified: 17 Aug 2017

    MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of service and execute arbitrary code via multiple attack vectors, as originally demonstrated using a crafted document record with a malformed string, as demonstrated by replacing a certain "01 00 00 00" byte sequence with an "FF FF FF FF" byte sequence, possibly causing an invalid array index, in (1) an Excel .xls document, which triggers an access violation in ole32.dll; (2) an Excel .xlw document, which triggers an access violation in excel.exe; (3) a Word document, which triggers an access violation in mso.dll in winword.exe; and (4) a PowerPoint document, which triggers an access violation in powerpnt.txt. NOTE: after the initial disclosure, this issue was demonstrated by triggering an integer overflow using an inconsistent size for a Unicode "Sheet Name" string.

    Source:posidron
    Published:30 Mar 2006
    7.5
    High

    CVE-2006-1536

    Last Modified: 11 Aug 2013

    Multiple SQL injection vulnerabilities in Phoetux.net PhxContacts 0.93.1 beta and earlier allow remote attackers to execute arbitrary SQL commands via the (1) motclef and (2) nbr_line_view parameters in (a) carnet.php, and the (3) id_contact parameter in (b) contact_view.php.

    Source:Morocco Security Team
    Published:30 Mar 2006
    4.3
    Medium

    CVE-2006-1535

    Last Modified: 11 Aug 2013

    Cross-site scripting (XSS) vulnerability in login.php in Phoetux.net PhxContacts 0.93.1 beta and earlier allows remote attackers to inject arbitrary web script or HTML via the m parameter.

    Source:DaBDouB-MoSiKaR
    Published:30 Mar 2006
    6.5
    Medium

    CVE-2006-1518

    Last Modified: 16 Apr 2026

    Buffer overflow in the open_table function in sql_base.cc in MySQL 5.0.x up to 5.0.20 might allow remote attackers to execute arbitrary code via crafted COM_TABLE_DUMP packets with invalid length values.

    Source:Stefano Di Paola
    Published:5 May 2006
    5
    Medium

    CVE-2006-1516

    Last Modified: 16 Apr 2026

    The check_connection function in sql_parse.cc in MySQL 4.0.x up to 4.0.26, 4.1.x up to 4.1.18, and 5.0.x up to 5.0.20 allows remote attackers to read portions of memory via a username without a trailing null byte, which causes a buffer over-read.

    Source:Stefano Di Paola
    Published:2 May 2006
    4
    Medium

    CVE-2006-1510

    Last Modified: 23 Aug 2013

    Buffer overflow in calloc.c in the Microsoft Windows XP SP2 ntdll.dll system library, when used by the ILDASM disassembler in the Microsoft .NET 1.0 and 1.1 SDK, might allow user-assisted attackers to execute arbitrary code via a crafted .dll file with a large static method.

    Source:Dinis Cruz
    Published:30 Mar 2006
    4.3
    Medium

    CVE-2006-1508

    Last Modified: 11 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in MH Software Connect Daily Web Calendar Software 3.2.9 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) calendar_id, (2) style_sheet, and (3) start parameters in (a) ViewDay.html; the (4) txtSearch and (5) opgSearch parameters in (b) ViewSearch.html; the (6) calendar_id and (7) approved parameters in (c) ViewYear.html; the (8) item_type_id parameter in (d) ViewCal.html; and the (9) week parameter in (e) ViewWeek.html.

    Source:r0t
    Published:30 Mar 2006
    5.1
    Medium

    CVE-2006-1504

    Last Modified: 2 Jan 2017

    Multiple cross-site scripting (XSS) vulnerabilities in Arab Portal 2.0 (aka Arab Dynamic Portal or ADP) stable allow remote attackers to inject arbitrary web script or HTML via the title parameter in (1) online.php and (2) download.php.

    Source:o.y.6
    Published:30 Mar 2006
    7.5
    High

    CVE-2006-1501

    Last Modified: 11 Aug 2013

    SQL injection vulnerability in index.php in OneOrZero 1.6.3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter, possibly in the kans action.

    Source:Preddy
    Published:30 Mar 2006
    5
    Medium

    CVE-2006-1497

    Last Modified: 10 Aug 2013

    Directory traversal vulnerability in index.php in ViHor Design allows remote attackers to read arbitrary files via the page parameter.

    Source:botan
    Published:30 Mar 2006
    4.3
    Medium

    CVE-2006-1496

    Last Modified: 10 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in ViHor Design allow remote attackers to inject arbitrary web script or HTML via (1) a remote URL in the page parameter, which is processed by an fopen call, or (2) HTML or script in the page parameter, which is returned to the client in an error message for the failed fopen call.

    Source:botan
    Published:30 Mar 2006
    7.5
    High

    CVE-2006-1495

    Last Modified: 30 Jun 2016

    SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 and 2.6.0b2 allows remote attackers to execute arbitrary SQL commands via the loginForm parameter in the "forgotten password" option.

    Source:rgod
    Published:30 Mar 2006
    2.6
    Low

    CVE-2006-1494

    Last Modified: 15 Aug 2013

    Directory traversal vulnerability in file.c in PHP 4.4.2 and 5.1.2 allows local users to bypass open_basedir restrictions allows remote attackers to create files in arbitrary directories via the tempnam function.

    Source:Maksymilian Arciemowicz
    Published:8 Apr 2006
    7.5
    High

    CVE-2006-1491

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in Horde Application Framework versions 3.0 before 3.0.10 and 3.1 before 3.1.1 allows remote attackers to execute arbitrary code via the help viewer.

    Source:Inkubus
    Published:29 Mar 2006
    5
    Medium

    CVE-2006-1490

    Last Modified: 26 Jun 2017

    PHP before 5.1.3-RC1 might allow remote attackers to obtain portions of memory via crafted binary data sent to a script that processes user input in the html_entity_decode function and sends the encoded results back to the client, aka a "binary safety" issue. NOTE: this issue has been referred to as a "memory leak," but it is an information leak that discloses memory contents.

    Source:Samuel
    Published:28 Mar 2006
    7.5
    High

    CVE-2006-1489

    Last Modified: 11 Aug 2013

    Multiple SQL injection vulnerabilities in FusionZONE CouponZONE local.cfm in 4.2 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) companyid, (2) scat, and (3) coid parameters.

    Source:r0t
    Published:29 Mar 2006
    4.3
    Medium

    CVE-2006-1487

    Last Modified: 11 Aug 2013

    Cross-site scripting (XSS) vulnerability in ActiveCampaign SupportTrio 2.50.2 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters to the KnowledgeBase search module.

    Source:r0t
    Published:29 Mar 2006
    4.3
    Medium

    CVE-2006-1486

    Last Modified: 11 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.

    Source:r0t
    Published:29 Mar 2006
    4.3
    Medium

    CVE-2006-1482

    Last Modified: 10 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in ConfTool 1.1 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:botan
    Published:29 Mar 2006
    6.5
    Medium

    CVE-2006-1481

    Last Modified: 30 Jun 2016

    SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL commands and obtain usernames and passwords via the frm_search_in parameter.

    Source:undefined1_
    Published:29 Mar 2006
    5.1
    Medium

    CVE-2006-1480

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and execute commands by (1) injecting code into local log files via GET commands, then (2) accessing that log via a .. (dot dot) sequence and a trailing null (%00) byte in the skin2 COOKIE parameter.

    Source:rgod
    Published:29 Mar 2006
    5
    Medium

    CVE-2006-1470

    Last Modified: 6 Sept 2013

    OpenLDAP in Apple Mac OS X 10.4 up to 10.4.6 allows remote attackers to cause a denial of service (crash) via an invalid LDAP request that triggers an assert error.

    Source:Mu Security research
    Published:27 Jun 2006
    4.3
    Medium

    CVE-2006-1431

    Last Modified: 11 Aug 2013

    Cross-site scripting (XSS) vulnerability in local.cfm in fusionZONE couponZONE 4.2 allows remote attackers to inject arbitrary web script or HTML via URL-encoded (1) srchfor and (2) srchby parameters.

    Source:r0t
    Published:28 Mar 2006
    4.3
    Medium

    CVE-2006-1430

    Last Modified: 11 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CONTROLzx HMS (formerly DRZES) 3.3.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) dedicatedPlanID parameter to dedicated_order.php, (2) sharedPlanID parameter to shared_order.php, (3) plan_id parameter to customers/server_management.php, and (4) email field to customers/forgotpass.php.

    Source:r0t
    Published:28 Mar 2006
    4.3
    Medium

    CVE-2006-1429

    Last Modified: 11 Aug 2013

    Cross-site scripting (XSS) vulnerability in accountlogon.cfm in classifiedZONE 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the rtn parameter.

    Source:r0t
    Published:28 Mar 2006
    4.3
    Medium

    CVE-2006-1428

    Last Modified: 11 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in phpCOIN 1.2.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the fs parameter to (1) mod.php or (2) mod_print.php.

    Source:r0t
    Published:28 Mar 2006