4.3
    Medium

    CVE-2006-1258

    Last Modified: 9 Aug 2013

    Cross-site scripting (XSS) vulnerability in phpMyAdmin 2.8.0.1 allows remote attackers to inject arbitrary web script or HTML via the set_theme parameter.

    Source:Ali Asad
    Published:19 Mar 2006
    10
    Critical

    CVE-2006-1255

    Last Modified: 27 Oct 2016

    Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a long string to the (1) LOGIN or (2) SELECT command, a different set of attack vectors and possibly a different vulnerability than CVE-2003-1177.

    Source:Metasploit
    Published:19 Mar 2006
    7.5
    High

    CVE-2006-1252

    Last Modified: 29 Jun 2016

    Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary PHP code via the date parameter to index.php.

    Source:Hessam-x
    Published:19 Mar 2006
    7.5
    High

    CVE-2006-1245

    Last Modified: 29 Jul 2016

    Buffer overflow in mshtml.dll in Microsoft Internet Explorer 6.0.2900.2180, and probably other versions, allows remote attackers to execute arbitrary code via an HTML tag with a large number of script action handlers such as onload and onmouseover, as demonstrated using onclick, aka the "Multiple Event Handler Memory Corruption Vulnerability."

    Source:Thomas Waldegger
    Published:17 Mar 2006
    7.5
    High

    CVE-2006-1243

    Last Modified: 29 Jun 2016

    Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers to include and execute arbitrary local files via directory traversal sequences and a NUL (%00) character in the blog_language parameter, as demonstrated by injecting PHP sequences into an Apache access_log file, which is then included using install05.php.

    Source:rgod
    Published:15 Mar 2006
    4.6
    Medium

    CVE-2006-1240

    Last Modified: 7 Aug 2013

    Buffer overflow in inet_server.cpp in (1) fb_inet_server and (2) fbserver in Firebird 1.5.2.4731 allows local users to gain privileges via a long value of the -p argument.

    Source:Joxean Koret
    Published:15 Mar 2006
    5.1
    Medium

    CVE-2006-1238

    Last Modified: 11 Aug 2013

    SQL injection vulnerability in DSLogin 1.0, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the $log_userid variable in (1) index.php and (2) admin/index.php.

    Source:Aliaksandr Hartsuyeu
    Published:15 Mar 2006
    7.3
    High

    CVE-2006-1236

    Last Modified: 30 Jun 2016

    Buffer overflow in the SetUp function in socket/request.c in CrossFire 1.9.0 allows remote attackers to execute arbitrary code via a long setup sound command, a different vulnerability than CVE-2006-1010.

    Source:landser
    Published:14 Mar 2006
    5.1
    Medium

    CVE-2006-1234

    Last Modified: 8 Aug 2013

    SQL injection vulnerability in index.php in DSCounter 1.2, with magic_quotes_gpc disabled, allows remote attackers to execute arbitrary SQL commands via the X-Forwarded-For field (HTTP_X_FORWARDED_FOR environment variable) in an HTTP header.

    Source:Aliaksandr Hartsuyeu
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1233

    Last Modified: 7 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.

    Source:R00T3RR0R
    Published:14 Mar 2006
    7.5
    High

    CVE-2006-1232

    Last Modified: 8 Aug 2013

    Multiple SQL injection vulnerabilities in DSDownload 1.0, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) key and (2) category parameters to (a) search.php and (b) downloads.php.

    Source:Aliaksandr Hartsuyeu
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1230

    Last Modified: 7 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in create.php in vCard 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) card_id, (2) uploaded, (3) card_fontsize, or (4) card_color parameter. NOTE: the card_id vector was later reported to affect vCard 2.9, and the uploaded vector for 2.6.

    Source:Linux_Drox
    Published:14 Mar 2006
    2.6
    Low

    CVE-2006-1224

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in dwnld.php in GuppY 4.5.11 allows remote attackers to overwrite arbitrary files via a "%2E." (mixed encoding) in the pg parameter.

    Source:trueend5
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1223

    Last Modified: 26 Sept 2016

    Cross-site scripting (XSS) vulnerability in Jupiter Content Manager 1.1.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a Javascript URI in the image BBcode tag.

    Source:Nomenumbra
    Published:14 Mar 2006
    5
    Medium

    CVE-2006-1219

    Last Modified: 29 Jun 2016

    Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include arbitrary PHP files via ".." (dot dot) sequences in the stepOrder parameter to (1) upgrade/index.php or (2) install/index.php.

    Source:rgod
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1216

    Last Modified: 28 Nov 2016

    Cross-site scripting (XSS) vulnerability in bigshow.php in Runcms 1.x allows remote attackers to inject arbitrary web script or HTML via the id parameter.

    Source:Roozbeh Afrasiabi
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1215

    Last Modified: 5 Aug 2013

    Cross-site scripting (XSS) vulnerability in misc.php in Woltlab Burning Board (wBB) 2.3.4 allows remote attackers to inject arbitrary web script or HTML via the percent parameter. NOTE: this issue has been disputed in a followup post, although the original disclosure might be related to reflected XSS.

    Source:r57shell
    Published:14 Mar 2006
    5
    Medium

    CVE-2006-1214

    Last Modified: 7 Aug 2013

    UnrealIRCd 3.2.3 allows remote attackers to cause an unspecified denial of service by causing a linked server to send malformed TKL Q:Line commands, as demonstrated by "TKL - q\x08Q *\x08PoC."

    Source:Brandon Milner
    Published:14 Mar 2006
    7.5
    High

    CVE-2006-1213

    Last Modified: 7 Feb 2018

    JiRo's Banner System Experience and Professional 1.0 and earlier allows remote attackers to bypass access restrictions and gain privileges via a direct request to certain scripts in the files directory, as demonstrated by using addadmin.asp to create a new administrator account.

    Source:nukedx
    Published:14 Mar 2006
    7.5
    High

    CVE-2006-1212

    Last Modified: 7 Aug 2013

    Unspecified vulnerability in index.php in Core CoreNews 2.0.1 allows remote attackers to execute arbitrary commands via the page parameter, possibly due to a PHP remote file include vulnerability. NOTE: this vulnerability could not be confirmed by source code inspection of CoreNews 2.0.1, which does not appear to use a "page" parameter or variable.

    Source:botan
    Published:14 Mar 2006
    5
    Medium

    CVE-2006-1209

    Last Modified: 20 Sept 2016

    PHP Advanced Transfer Manager 1.00 through 1.30 stores sensitive information, including password hashes, under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for a users/[USERNAME] file.

    Source:Kacper
    Published:14 Mar 2006
    5
    Medium

    CVE-2006-1206

    Last Modified: 29 Jun 2016

    Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.

    Source:str0ke
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1205

    Last Modified: 14 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in myWebland myBloggie 2.1.3 beta and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) confirmredirect and (2) post_id parameters in (a) delcomment.php, as reachable when mode=delcom from index.php; and the (3) del and (4) message parameters in (b) upload.php, the (5) errormsg parameter in (c) addcat.php, (d) edituser.php, (e) adduser.php, and (f) editcat.php, the (6) trackback_url parameter in (g) add.php, (7) id parameter in (h) deluser.php, (8) cat_id parameter in (i) delcat.php, and (9) post_id parameter in (j) del.php, as reachable from admin.php.

    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1202

    Last Modified: 6 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.

    Source:Retard
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1199

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in iframe.php in daverave Link Bank allows remote attackers to inject arbitrary web script or HTML via the site parameter.

    Source:Retard
    Published:14 Mar 2006
    4.3
    Medium

    CVE-2006-1196

    Last Modified: 7 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.

    Source:Kiki
    Published:13 Mar 2006
    5
    Medium

    CVE-2006-1194

    Last Modified: 7 Aug 2013

    Integer signedness error in the enet_protocol_handle_incoming_commands function in protocol.c for ENet library CVS version Jul 2005 and earlier, as used in products including (1) Cube, (2) Sauerbraten, and (3) Duke3d_w32, allows remote attackers to cause a denial of service (application crash) via a packet with a large command length value, which leads to an invalid memory access.

    Source:Luigi Auriemma
    Published:13 Mar 2006
    2.6
    Low

    CVE-2006-1193

    Last Modified: 1 Sept 2013

    Cross-site scripting (XSS) vulnerability in Microsoft Exchange Server 2000 SP1 through SP3, when running Outlook Web Access (OWA), allows user-assisted remote attackers to inject arbitrary HTML or web script via unknown vectors related to "HTML parsing."

    Source:Daniel Fabian
    Published:13 Jun 2006
    2.6
    Low

    CVE-2006-1192

    Last Modified: 29 Jul 2016

    Microsoft Internet Explorer 5.01 through 6 allows remote attackers to conduct phishing attacks by spoofing the address bar and other parts of the trust UI via unknown methods that allow "window content to persist" after the user has navigated to another site, aka the "Address Bar Spoofing Vulnerability." NOTE: this is a different vulnerability than CVE-2006-1626.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    4
    Medium

    CVE-2006-1191

    Last Modified: 29 Jul 2016

    Microsoft Internet Explorer 5.01 through 6 does not always correctly identify the domain that is associated with a browser window, which allows remote attackers to obtain sensitive cross-domain information and spoof sites by running script after the user has navigated to another site.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    10
    Critical

    CVE-2006-1190

    Last Modified: 29 Jul 2016

    Microsoft Internet Explorer 5.01 through 6 does not always return the correct IOleClientSite information when dynamically creating an embedded object, which could cause Internet Explorer to run the object in the wrong security context or zone, and allow remote attackers to execute arbitrary code.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    10
    Critical

    CVE-2006-1189

    Last Modified: 29 Jul 2016

    Buffer overflow in URLMON.DLL in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via a crafted URL with an International Domain Name (IDN) using double-byte character sets (DBCS), aka the "Double Byte Character Parsing Memory Corruption Vulnerability."

    Source:Thomas Waldegger
    Published:11 Apr 2006
    7.5
    High

    CVE-2006-1188

    Last Modified: 29 Jul 2016

    Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via HTML elements with a certain crafted tag, which leads to memory corruption.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    10
    Critical

    CVE-2006-1186

    Last Modified: 29 Jul 2016

    Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via by instantiating the (1) Mdt2gddr.dll, (2) Mdt2dd.dll, and (3) Mdt2gddo.dll COM objects as ActiveX controls, which leads to memory corruption.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    7.5
    High

    CVE-2006-1185

    Last Modified: 29 Jul 2016

    Unspecified vulnerability in Microsoft Internet Explorer 5.01 through 6 allows remote attackers to execute arbitrary code via certain invalid HTML that causes memory corruption.

    Source:Thomas Waldegger
    Published:11 Apr 2006
    7.2
    High

    CVE-2006-1183

    Last Modified: 16 Apr 2026

    The Ubuntu 5.10 installer does not properly clear passwords from the installer log file (questions.dat), and leaves the log file with world-readable permissions, which allows local users to gain privileges.

    Source:Kristian Hermansen
    Published:13 Mar 2006
    5
    Medium

    CVE-2006-1172

    Last Modified: 24 Aug 2013

    Stack-based buffer overflow in the createPKCS10 function in Cryptomathic Cenroll ActiveX Control 1.1.0.0 allows remote attackers to execute arbitrary code via vectors related to the TDC Digital signature.

    Source:Dennis Rand
    Published:9 May 2006
    7.5
    High

    CVE-2006-1164

    Last Modified: 16 Apr 2026

    Nodez 4.6.1.1 and earlier stores sensitive data in the list.gtdat file under the web document root with insufficient access control, which allows remote attackers to obtain usernames and password hashes by directly accessing list.gtdat.

    Source:rgod
    Published:12 Mar 2006
    5.1
    Medium

    CVE-2006-1162

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in Nodez 4.6.1.1 and earlier allows remote attackers to read or include arbitrary PHP files via a .. (dot dot) in the op parameter, as demonstrated by inserting malicious Email parameters into list.gtdat, then accessing list.gtdat using the op parameter.

    Source:rgod
    Published:12 Mar 2006
    6.5
    Medium

    CVE-2006-1161

    Last Modified: 7 Aug 2013

    Absolute path traversal vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote registered users to execute arbitrary code by uploading a malicious file to the Windows startup folder.

    Source:Revnic Vasile
    Published:12 Mar 2006
    7.8
    High

    CVE-2006-1159

    Last Modified: 7 Aug 2013

    Format string vulnerability in Easy File Sharing (EFS) Web Server 3.2 allows remote attackers to cause a denial of service (server crash) and possibly execute arbitrary code via format string specifiers in the query string argument in an HTTP GET request.

    Source:Revnic Vasile
    Published:12 Mar 2006
    4.3
    Medium

    CVE-2006-1157

    Last Modified: 7 Aug 2013

    Cross-site scripting (XSS) vulnerability in Vz Scripts ADP Forum 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the Subject field (possibly messaggio parameter) when posting a new message in post.php.

    Source:liz0
    Published:12 Mar 2006
    5
    Medium

    CVE-2006-1153

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in D2-Shoutbox 4.2 allows remote attackers to execute arbitrary SQL commands via the load parameter, when performing a Shoutbox action through Invision Power Board (IPB).

    Source:SkOd
    Published:10 Mar 2006
    5
    Medium

    CVE-2006-1151

    Last Modified: 26 Dec 2013

    Cross-site scripting vulnerability in index.php in M-Phorum 0.2 allows remote attackers to inject arbitrary web script or HTML via the go parameter.

    Source:CodeXpLoder'tq
    Published:10 Mar 2006
    7.5
    High

    CVE-2006-1149

    Last Modified: 29 Jun 2016

    PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled, allows remote attackers to include arbitrary files via a URL in the xrms_file_root parameter, which is not initialized before use.

    Source:rgod
    Published:10 Mar 2006
    7.5
    High

    CVE-2006-1148

    Last Modified: 6 Mar 2011

    Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow remote attackers to execute arbitrary code via an HTTP GET request with a long (1) parameter name or (2) value in a URL, which triggers the overflow in the nextCGIarg function in servhs.cpp.

    Source:Metasploit
    Published:10 Mar 2006
    4
    Medium

    CVE-2006-1147

    Last Modified: 16 Apr 2026

    The Com_sprintf function in q_shared.c in Alien Arena 2006 Gold Edition 5.00 does not properly NULL terminate certain long strings, which allows remote attackers (possibly authenticated) to cause a denial of service (application crash) via a long skin, weapon, or model name.

    Source:Luigi Auriemma
    Published:10 Mar 2006
    6.5
    Medium

    CVE-2006-1146

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in the Cmd_Say_f function in g_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code by sending a long message to the server.

    Source:Luigi Auriemma
    Published:10 Mar 2006
    6.5
    Medium

    CVE-2006-1145

    Last Modified: 16 Apr 2026

    Format string vulnerability in the safe_cprintf function in acebot_cmds.c in Alien Arena 2006 Gold Edition 5.00 allows remote attackers (possibly authenticated) to execute arbitrary code via unspecified vectors when the server sends crafted messages to the clients.

    Source:Luigi Auriemma
    Published:10 Mar 2006
    2.6
    Low

    CVE-2006-1144

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.

    Source:Retard
    Published:10 Mar 2006