7.5
    High

    CVE-2006-1140

    Last Modified: 29 Jun 2016

    SQL injection vulnerability in rss.php in RedBLoG 0.5 allows remote attackers to execute arbitrary SQL commands via the cat_id parameter.

    Source:x128
    Published:10 Mar 2006
    4.3
    Medium

    CVE-2006-1135

    Last Modified: 6 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in sBlog 0.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to search.php or (2) username parameter to comments_do.php.

    Source:Kiki
    Published:10 Mar 2006
    4.3
    Medium

    CVE-2006-1133

    Last Modified: 5 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in vbzoom 1.11 allow remote attackers to inject arbitrary web script or HTML via the UserID parameter to (1) comment.php or (2) contact.php. NOTE: the profile.php/UserName vector is already covered by CVE-2005-2441.

    Source:Mr.SNAKE
    Published:10 Mar 2006
    7.5
    High

    CVE-2006-1132

    Last Modified: 5 Aug 2013

    SQL injection vulnerability in show.php in vbzoom 1.11 allow remote attackers to execute arbitrary SQL commands via the MainID parameter. NOTE: the SubjectID vector is already covered by CVE-2005-4729.

    Source:Mr.SNAKE
    Published:10 Mar 2006
    4.3
    Medium

    CVE-2006-1131

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in read.php in bitweaver CMS 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the comment_title parameter.

    Source:Kiki
    Published:10 Mar 2006
    6.4
    Medium

    CVE-2006-1128

    Last Modified: 19 Jan 2018

    Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows remote attackers to access and delete files by specifying the session in a cookie, which is used in constructing file paths before the session value is sanitized.

    Source:GulfTech Security
    Published:9 Mar 2006
    4.3
    Medium

    CVE-2006-1127

    Last Modified: 19 Jan 2018

    Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script or HTML via the X-Forwarded-For (X_FORWARDED_FOR) HTTP header, which is not properly handled when adding a comment to an album.

    Source:GulfTech Security
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1124

    Last Modified: 16 Apr 2026

    Buffer overflow in RevilloC MailServer and Proxy 1.21 allows remote attackers to execute arbitrary code via a long USER command.

    Source:securma massine
    Published:9 Mar 2006
    10
    Critical

    CVE-2006-1123

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in D2KBlog 1.0.3 and earlier allows remote attackers to execute arbitrary SQL commands via the memName parameter in a cookie.

    Source:DevilBox
    Published:9 Mar 2006
    6.8
    Medium

    CVE-2006-1121

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the query string to index.php.

    Source:Roozbeh Afrasiabi
    Published:9 Mar 2006
    2.6
    Low

    CVE-2006-1120

    Last Modified: 7 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 6.1.1 and earlier, with register_globals enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) its_url parameter in the documents page and (2) url parameter in the send_write page of (a) index.php; (3) subject, and (4) images parameters to (b) calendar.php; (5) bid, (6) replying_msg, (7) subject, (8) body, and (9) mid parameters to (c) forums.php; (10) subject and (11) message parameters to (d) inbox.php; (12) subject_color and (13) email parameters to (e) lostpassword.php; and the (14) c_name, (15) content_inicial, and (16) cid parameters to (f) mycontents.php. NOTE: the calendar.php/day vector is already subsumed by CVE-2006-0220, and the calendar.php/month, calendar.php/year, and search.php/q parameters for calendar.php are already subsumed by CVE-2004-2511.

    Source:Nenad Jovanovic
    Published:9 Mar 2006
    6.4
    Medium

    CVE-2006-1114

    Last Modified: 2 Jan 2017

    Multiple directory traversal vulnerabilities in Loudblog before 0.42 allow remote attackers to read or include arbitrary files via a .. (dot dot) and trailing %00 (NULL) byte in the (1) template and (2) page parameters in (a) index.php, and the (3) language parameter in (b) inc/backend_settings.php.

    Source:tzitaroth
    Published:9 Mar 2006
    5
    Medium

    CVE-2006-1113

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in podcast.php in Loudblog before 0.42 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:tzitaroth
    Published:9 Mar 2006
    5
    Medium

    CVE-2006-1112

    Last Modified: 16 Apr 2026

    Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which displays the installation path in a MySQL error message.

    Source:lorenzo
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1111

    Last Modified: 16 Apr 2026

    Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, which reveals usernames and passwords in a MySQL error message, possibly due to a forced SQL error or SQL injection.

    Source:lorenzo
    Published:9 Mar 2006
    4.3
    Medium

    CVE-2006-1110

    Last Modified: 16 Apr 2026

    Cross-site scripting (XSS) vulnerability in Aztek Forum 4.0 allows remote attackers to inject arbitrary web script or HTML via the message body in a new message.

    Source:lorenzo
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1109

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in index.asp in Total Ecommerce 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: it is not clear whether this report is associated with a specific product. If not, then it should not be included in CVE.

    Source:nukedx
    Published:9 Mar 2006
    5
    Medium

    CVE-2006-1103

    Last Modified: 16 Apr 2026

    engine/server.cpp in Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (segmentation fault) via a client that does not completely join the game and times out, which results in a null pointer dereference.

    Source:Luigi Auriemma
    Published:9 Mar 2006
    5
    Medium

    CVE-2006-1102

    Last Modified: 16 Apr 2026

    Sauerbraten 2006_02_28, as derived from the Cube engine, allows remote attackers to cause a denial of service (client exit) by forcing the server to change to a map (ogz) file whose name contains ".." sequences and has a certain length that prevents the addition of the ".ogz" extension.

    Source:Luigi Auriemma
    Published:9 Mar 2006
    5
    Medium

    CVE-2006-1101

    Last Modified: 16 Apr 2026

    The (1) sgetstr and (2) getint functions in Sauerbraten 2006_02_28, as derived from the Cube engine, allow remote attackers to cause a denial of service (segmentation fault) via long streams of input data that trigger an out-of-bounds read, as demonstrated using SV_EXT tag data in the Cube engine, which is not properly handled by getint.

    Source:Luigi Auriemma
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1100

    Last Modified: 16 Apr 2026

    Buffer overflow in the sgetstr function in shared/cube.h in Sauerbraten 2006_02_28 and earlier, as derived from the Cube engine, allows remote attackers to execute arbitrary code via long streams of input data.

    Source:Luigi Auriemma
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1099

    Last Modified: 5 Aug 2013

    PHP remote file include vulnerability in logIT 1.3 and 1.4 allows remote attackers to execute arbitrary PHP code via a URL in the pg parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:botan
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1098

    Last Modified: 5 Aug 2013

    Multiple SQL injection vulnerabilities in NZ Ecommerce allow remote attackers to execute arbitrary SQL commands via the (1) informationID or (2) ParentCategory parameter to index.php. NOTE: the vendor has disputed this issue in a comment on the researcher's blog, but research by CVE suggests that this might be a legitimate problem

    Source:r0t
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1094

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.

    Source:nukedx
    Published:9 Mar 2006
    7.8
    High

    CVE-2006-1090

    Last Modified: 11 Nov 2016

    register.php in PunBB 1.2.10 allows remote attackers to cause an unspecified denial of service via a flood of new user registrations.

    Source:K4P0
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1081

    Last Modified: 5 Aug 2013

    SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers to execute arbitrary SQL commands via the email parameter.

    Source:Hamid Ebadi
    Published:9 Mar 2006
    4.3
    Medium

    CVE-2006-1080

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the message parameter, possibly requiring a URL encoded value.

    Source:Retard
    Published:9 Mar 2006
    7.5
    High

    CVE-2006-1076

    Last Modified: 6 Aug 2013

    SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 allows remote attackers to execute arbitrary SQL commands via the st parameter.

    Source:Mr.SNAKE
    Published:9 Mar 2006
    6.4
    Medium

    CVE-2006-1073

    Last Modified: 6 Aug 2013

    Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include or read arbitrary .txt files via the (1) act and (2) blogid parameters.

    Source:Retard
    Published:8 Mar 2006
    4.3
    Medium

    CVE-2006-1071

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Liz0ziM
    Published:8 Mar 2006
    4.3
    Medium

    CVE-2006-1070

    Last Modified: 6 Aug 2013

    Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary web script or HTML via the f parameter.

    Source:Liz0ziM
    Published:8 Mar 2006
    5
    Medium

    CVE-2006-1046

    Last Modified: 13 Aug 2013

    server.cpp in Monopd 0.9.3 allows remote attackers to cause a denial of service (CPU and memory consumption) via a string containing a large number of characters that are escaped when Monopd produces XML output.

    Source:Luigi Auriemma
    Published:7 Mar 2006
    2.6
    Low

    CVE-2006-1045

    Last Modified: 5 Aug 2013

    The HTML rendering engine in Mozilla Thunderbird 1.5, when "Block loading of remote images in mail messages" is enabled, does not properly block external images from inline HTML attachments, which could allow remote attackers to obtain sensitive information, such as application version or IP address, when the user reads the email and the external image is accessed.

    Source:Crashfr
    Published:28 Feb 2006
    5.1
    Medium

    CVE-2006-1043

    Last Modified: 16 Apr 2026

    Stack-based buffer overflow in Microsoft Visual Studio 6.0 and Microsoft Visual InterDev 6.0 allows user-assisted attackers to execute arbitrary code via a long DataProject field in a (1) Visual Studio Database Project File (.dbp) or (2) Visual Studio Solution (.sln).

    Source:Kozan
    Published:7 Mar 2006
    4.3
    Medium

    CVE-2006-1040

    Last Modified: 5 Aug 2013

    Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.

    Source:imei
    Published:7 Mar 2006
    6.4
    Medium

    CVE-2006-1039

    Last Modified: 27 Aug 2013

    SAP Web Application Server (WebAS) Kernel before 7.0 allows remote attackers to inject arbitrary bytes into the HTTP response and obtain sensitive authentication information, or have other impacts, via a ";%20" followed by encoded HTTP headers.

    Source:Arnold Grossmann
    Published:7 Mar 2006
    4.3
    Medium

    CVE-2006-1034

    Last Modified: 4 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbitrary web script or HTML via (1) the username parameter to galerie_index.php and possibly (2) galerie_onfly.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. The second vector might not be XSS.

    Source:botan
    Published:7 Mar 2006
    4.3
    Medium

    CVE-2006-1033

    Last Modified: 2 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.

    Source:Lostmon
    Published:7 Mar 2006
    7.5
    High

    CVE-2006-1032

    Last Modified: 19 Jan 2018

    Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, exoops, and possibly other programs, allows remote attackers to execute arbitrary PHP code via the base64 tag.

    Source:GulfTech Security
    Published:7 Mar 2006
    7.5
    High

    CVE-2006-1031

    Last Modified: 16 Apr 2026

    config/config_inc.php in iGENUS Webmail 2.02 and earlier allows remote attackers to include arbitrary local files via the SG_HOME parameter.

    Source:rgod
    Published:7 Mar 2006
    5
    Medium

    CVE-2006-1022

    Last Modified: 5 Aug 2013

    PHP remote file include vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to include and execute arbitrary PHP code via a URL in the uye_klasor parameter, along with a misafir[] parameter that is set to UYE_SEVIYE.

    Source:Yunus Emre Yilmaz
    Published:7 Mar 2006
    4.3
    Medium

    CVE-2006-1021

    Last Modified: 5 Aug 2013

    Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management System) 3 allows remote attackers to inject arbitrary web script or HTML via the kuladi parameter ($kul_adi variable).

    Source:Yunus Emre Yilmaz
    Published:7 Mar 2006
    7.5
    High

    CVE-2006-1018

    Last Modified: 5 Aug 2013

    SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL commands via the id parameter in a diwan view action.

    Source:sherba
    Published:7 Mar 2006
    7.5
    High

    CVE-2006-1016

    Last Modified: 10 Mar 2011

    Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Windows XP before SP1, allows remote attackers to execute arbitrary code via JavaScript that calls IsComponentInstalled with a long first argument.

    Source:Metasploit
    Published:7 Mar 2006
    6.4
    Medium

    CVE-2006-1015

    Last Modified: 4 Aug 2013

    Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mail function, allows remote attackers to read and create arbitrary files via the sendmail -C and -X arguments. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

    Published:7 Mar 2006
    3.2
    Low

    CVE-2006-1014

    Last Modified: 4 Aug 2013

    Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting remote input for the additional_parameters argument to the mb_send_mail function, allows context-dependent attackers to read and create arbitrary files by providing extra -C and -X arguments to sendmail. NOTE: it could be argued that this is a class of technology-specific vulnerability, instead of a particular instance; if so, then this should not be included in CVE.

    Published:7 Mar 2006
    7.5
    High

    CVE-2006-1013

    Last Modified: 5 Aug 2013

    PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and execute arbitrary PHP files via (1) the pg parameter and (2) a query string without a parameter.

    Source:botan
    Published:7 Mar 2006
    6.4
    Medium

    CVE-2006-1010

    Last Modified: 29 Jun 2016

    Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to cause a denial of service (segmentation fault) and possibly execute code by sending the server a large request.

    Source:Luigi Auriemma
    Published:6 Mar 2006
    5.8
    Medium

    CVE-2006-1008

    Last Modified: 4 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to inject arbitrary web script or HTML via the (1) dir and (2) page_id parameter to (a) index.php and (3) userid parameter to (b) mailto.php. NOTE: it is possible that issues 1 and 2 are resultant from SQL injection.

    Source:Liz0ziM
    Published:6 Mar 2006
    7.5
    High

    CVE-2006-1007

    Last Modified: 4 Aug 2013

    Multiple SQL injection vulnerabilities in N8cms 1.1 and 1.2 allow remote attackers to execute arbitrary SQL commands via the (1) dir and (2) page_id parameter to index.php.

    Source:Liz0ziM
    Published:6 Mar 2006