5
    Medium

    CVE-2006-1001

    Last Modified: 29 Jun 2016

    SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote attackers to execute arbitrary SQL commands via the fid parameter.

    Source:x128
    Published:6 Mar 2006
    10
    Critical

    CVE-2006-1000

    Last Modified: 16 Apr 2026

    Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) newsid parameter to newsdetailsview.asp and (2) password parameter to login.asp.

    Source:nukedx
    Published:6 Mar 2006
    4.3
    Medium

    CVE-2006-0996

    Last Modified: 13 Aug 2013

    Cross-site scripting (XSS) vulnerability in phpinfo (info.c) in PHP 5.1.2 and 4.4.2 allows remote attackers to inject arbitrary web script or HTML via long array variables, including (1) a large number of dimensions or (2) long values, which prevents HTML tags from being removed.

    Source:Maksymilian Arciemowicz
    Published:30 Mar 2006
    10
    Critical

    CVE-2006-0992

    Last Modified: 9 Mar 2011

    Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute arbitrary code via a long Accept-Language value without a comma or semicolon. NOTE: due to a typo, the original ZDI advisory accidentally referenced CVE-2006-0092. This is the correct identifier.

    Source:Metasploit
    Published:14 Apr 2006
    5
    Medium

    CVE-2006-0987

    Last Modified: 16 Apr 2026

    The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.

    Published:3 Mar 2006
    4.3
    Medium

    CVE-2006-0984

    Last Modified: 4 Aug 2013

    Cross-site scripting (XSS) vulnerability in inc_header.php in EJ3 TOPo 2.2.178 allows remote attackers to inject arbitrary web script or HTML via the gTopNombre parameter.

    Source:Yunus Emre Yilmaz
    Published:3 Mar 2006
    4.3
    Medium

    CVE-2006-0983

    Last Modified: 4 Aug 2013

    Cross-site scripting (XSS) vulnerability in index.php in QwikiWiki 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter.

    Source:Dr^Death
    Published:3 Mar 2006
    5
    Medium

    CVE-2006-0976

    Last Modified: 3 Aug 2013

    Directory traversal vulnerability in scan_lang_insert.php in Boris Herbiniere-Seve SPiD 1.3.1 allows remote attackers to read arbitrary files via the lang parameter.

    Source:NSA Group
    Published:3 Mar 2006
    4.3
    Medium

    CVE-2006-0974

    Last Modified: 3 Aug 2013

    Cross-site scripting (XSS) vulnerability in failure.asp in Battleaxe bttlxeForum 2.0 allows remote attackers to inject arbitrary web script or HTML via the err_txt parameter.

    Source:rUnViRuS
    Published:3 Mar 2006
    7.5
    High

    CVE-2006-0973

    Last Modified: 29 Jun 2016

    SQL injection vulnerability in topics.php in Appalachian State University phpWebSite 0.10.2 and earlier allows remote attackers to execute arbitrary SQL commands via the topic parameter.

    Source:SnIpEr_SA
    Published:3 Mar 2006
    5
    Medium

    CVE-2006-0972

    Last Modified: 4 Aug 2013

    SQL injection vulnerability in news.php in Tony Baird Fantastic News 2.1.1 allows remote attackers to execute arbitrary SQL commands via the page parameter. NOTE: the category vector is already covered by CVE-2005-3846.

    Source:SAUDI
    Published:3 Mar 2006
    5
    Medium

    CVE-2006-0971

    Last Modified: 4 Aug 2013

    Directory traversal vulnerability in Lionel Reyero DirectContact 0.3b allows remote attackers to read arbitrary files via a .. (dot dot) in the URL.

    Source:Donato Ferrante
    Published:3 Mar 2006
    7.5
    High

    CVE-2006-0962

    Last Modified: 22 Nov 2017

    SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter in a cookie.

    Source:KingOfSka
    Published:2 Mar 2006
    7.5
    High

    CVE-2006-0961

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands via the haber_id parameter. NOTE: this product has also been referred to as "Cilem News," although that does not appear to be the proper name.

    Source:nukedx
    Published:2 Mar 2006
    7.5
    High

    CVE-2006-0959

    Last Modified: 9 Nov 2016

    SQL injection vulnerability in misc.php in MyBulletinBoard (MyBB) 1.03, when register_globals is enabled, allows remote attackers to execute arbitrary SQL commands by setting the comma variable value via the comma parameter in a cookie. NOTE: 1.04 has also been reported to be affected.

    Source:Devil-00
    Published:2 Mar 2006
    7.5
    High

    CVE-2006-0947

    Last Modified: 4 Aug 2013

    Thomson SpeedTouch modem running firmware 5.3.2.6.0 allows remote attackers to create users that cannot be deleted via scripting code in the "31" parameter in a NewUser function, which is not filtered by the modem when creating the account, but cannot be deleted by the administrator, possibly due to cleansing that occurs in the administrator interface.

    Source:Preben Nylokken
    Published:1 Mar 2006
    4.3
    Medium

    CVE-2006-0946

    Last Modified: 19 Jul 2017

    Cross-site scripting (XSS) vulnerability in Thomson SpeedTouch modems running firmware 5.3.2.6.0 allows remote attackers to inject arbitrary web script or HTML via the name parameter to the LocalNetwork page.

    Source:Preben Nylokken
    Published:1 Mar 2006
    7.5
    High

    CVE-2006-0944

    Last Modified: 4 Aug 2013

    Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.

    Source:KingOfSka
    Published:1 Mar 2006
    7.5
    High

    CVE-2006-0943

    Last Modified: 16 Apr 2026

    SQL injection vulnerability in the sondages module in index.php in PwsPHP 1.2.3 allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.

    Source:papipsycho
    Published:1 Mar 2006
    7.5
    High

    CVE-2006-0942

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to execute arbitrary SQL commands via the aff_news_form parameter, a different vulnerability than CVE-2005-1509.

    Source:papipsycho
    Published:1 Mar 2006
    7.5
    High

    CVE-2006-0940

    Last Modified: 16 Apr 2026

    Multiple direct static code injection vulnerabilities in savesettings.php in ShoutLIVE 1.1.0 allow remote attackers to execute arbitrary PHP code via variables that are written to settings.php.

    Source:DarkFig
    Published:1 Mar 2006
    7.5
    High

    CVE-2006-0939

    Last Modified: 3 Aug 2013

    SQL injection vulnerability in DCI-Taskeen 1.03 allows remote attackers to execute arbitrary SQL commands via the (1) id or (2) action parameter to (a) basket.php, or (3) id or (4) page parameter to (b) cat.php.

    Source:Linux_Drox
    Published:1 Mar 2006
    6.5
    Medium

    CVE-2006-0936

    Last Modified: 3 Aug 2013

    Free Host Shop Website Generator 3.3 allows remote authenticated users with administrative privileges to upload and execute arbitrary files via a formname parameter with a filename containing a dangerous file extension and a trailing %00.

    Source:NSA Group
    Published:28 Feb 2006
    4.3
    Medium

    CVE-2006-0933

    Last Modified: 3 Aug 2013

    Cross-site scripting (XSS) vulnerability in PHPX 3.5.9 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a url XCode tag in a posted message. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Thomas Pollet
    Published:28 Feb 2006
    2.6
    Low

    CVE-2006-0927

    Last Modified: 3 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.

    Source:nuker
    Published:28 Feb 2006
    5
    Medium

    CVE-2006-0925

    Last Modified: 4 Aug 2013

    Format string vulnerability in the IMAP4rev1 server in Alt-N MDaemon 8.1.1 and possibly 8.1.4 allows remote attackers to cause a denial of service (CPU consumption) by creating and then listing folders whose names contain format string specifiers.

    Source:Nemesis
    Published:28 Feb 2006
    4.3
    Medium

    CVE-2006-0923

    Last Modified: 23 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.

    Source:Mustafa Can Bjorn
    Published:28 Feb 2006
    5
    Medium

    CVE-2006-0922

    Last Modified: 3 Aug 2013

    CubeCart 3.0 through 3.6 does not properly check authorization for an administration session because of a missing auth.inc.php include, which results in an absolute path traversal vulnerability in FileUpload in connector.php (aka upload.php) that allows remote attackers to upload arbitrary files via a modified CurrentFolder parameter in a direct request to admin/filemanager/upload.php.

    Source:NSA Group
    Published:28 Feb 2006
    1.7
    Low

    CVE-2006-0920

    Last Modified: 3 Aug 2013

    Oi! Email Marketing System 3.0 (aka Oi! 3) stores the server's FTP password in cleartext on a Configuration web page, which allows local users with superadministrator privileges, or attackers who have obtained access to the web page, to view the password.

    Source:h4cky0u
    Published:28 Feb 2006
    5
    Medium

    CVE-2006-0911

    Last Modified: 2 Aug 2013

    NmService.exe in Ipswitch WhatsUp Professional 2006 allows remote attackers to cause a denial of service (CPU consumption) via crafted requests to Login.asp, possibly involving the (1) "In]" and (2) "b;tnLogIn" parameters, or (3) malformed btnLogIn parameters, possibly involving missing "[" (open bracket) or "[" (closing bracket) characters, as demonstrated by "&btnLogIn=[Log&In]=&" or "&b;tnLogIn=[Log&In]=&" in the URL. NOTE: due to the lack of diagnosis by the original researcher, the precise nature of the vulnerability is unclear.

    Source:Josh Zlatin-Amishav
    Published:28 Feb 2006
    7.5
    High

    CVE-2006-0906

    Last Modified: 4 Aug 2013

    SQL injection vulnerability in D3Jeeb Pro 3 allows remote attackers to execute arbitrary SQL commands via the catid parameter in (1) fastlinks.php and (2) catogary.php.

    Source:SAUDI
    Published:28 Feb 2006
    4.6
    Medium

    CVE-2006-0903

    Last Modified: 4 Aug 2013

    MySQL 5.0.18 and earlier allows local users to bypass logging mechanisms via SQL queries that contain the NULL character, which are not properly handled by the mysql_real_query function. NOTE: this issue was originally reported for the mysql_query function, but the vendor states that since mysql_query expects a null character, this is not an issue for mysql_query.

    Source:1dt.w0lf
    Published:20 Feb 2006
    7.8
    High

    CVE-2006-0900

    Last Modified: 4 Oct 2017

    nfsd in FreeBSD 6.0 kernel allows remote attackers to cause a denial of service via a crafted NFS mount request, as demonstrated by the ProtoVer NFS test suite.

    Source:Evgeny Legerov
    Published:27 Feb 2006
    7.5
    High

    CVE-2006-0899

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include arbitrary files via ".." (dot dot) sequences in the template parameter.

    Source:rgod
    Published:27 Feb 2006
    4.3
    Medium

    CVE-2006-0894

    Last Modified: 3 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php.

    Source:rgod
    Published:25 Feb 2006
    5
    Medium

    CVE-2006-0891

    Last Modified: 29 Jun 2016

    Multiple directory traversal vulnerabilities in NOCC Webmail 1.0 allow remote attackers to include arbitrary files via .. (dot dot) sequences and a trailing NULL (%00) byte in (1) the _SESSION['nocc_theme'] parameter in (a) html/footer.php; and (2) the lang and (3) theme parameters and the (4) Accept-Language HTTP header field, when force_default_lang is disabled, in (b) index.php, as demonstrated by injecting PHP code into a profile and accessing it using the lang parameter in index.php.

    Source:rgod
    Published:25 Feb 2006
    2.6
    Low

    CVE-2006-0888

    Last Modified: 16 Apr 2026

    index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unspecified denial of service by registering a large number of users.

    Source:SeeMe
    Published:25 Feb 2006
    7.5
    High

    CVE-2006-0887

    Last Modified: 19 Jan 2018

    Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib distribution is available on the server, allows remote attackers to execute arbitrary PHP code by including a base64-encoded representation of the code in a cookie. NOTE: this description was significantly updated on 20060605 to reflect new details after an initial vague advisory.

    Source:GulfTech Security
    Published:25 Feb 2006
    4.3
    Medium

    CVE-2006-0885

    Last Modified: 8 Dec 2016

    Cross-site scripting (XSS) vulnerability in show_news.php in CuteNews 1.4.1 allows remote attackers to inject arbitrary web script or HTML via the show parameter.

    Source:imei
    Published:25 Feb 2006
    9.3
    Critical

    CVE-2006-0884

    Last Modified: 2 Aug 2013

    The WYSIWYG rendering engine ("rich mail" editor) in Mozilla Thunderbird 1.0.7 and earlier allows user-assisted attackers to bypass javascript security settings and obtain sensitive information or cause a crash via an e-mail containing a javascript URI in the SRC attribute of an IFRAME tag, which is executed when the user edits the e-mail.

    Source:Georgi Guninski
    Published:24 Feb 2006
    5
    Medium

    CVE-2006-0882

    Last Modified: 2 Aug 2013

    Directory traversal vulnerability in include.php in Noah's Classifieds 1.3 allows remote attackers to include arbitrary local files via the otherTemplate parameter to index.php.

    Source:trueend5
    Published:24 Feb 2006
    7.5
    High

    CVE-2006-0881

    Last Modified: 2 Aug 2013

    Multiple PHP remote file include vulnerabilities in gorum/gorumlib.php in Noah's Classifieds 1.3, when register_globals is enabled, allow remote attackers to include arbitrary PHP files via the (1) upperTemplate and (2) lowerTemplate parameters, as demonstrated using the lowerTemplate parameter to index.php.

    Source:trueend5
    Published:24 Feb 2006
    4.3
    Medium

    CVE-2006-0880

    Last Modified: 2 Aug 2013

    Multiple cross-site scripting (XSS) vulnerabilities in index.php in Noah's Classifieds 1.3 allow remote attackers to inject arbitrary web script or HTML via the (1) inf parameter; or, when register_globals is enabled, the (2) upperTemplate and (3) lowerTemplate parameters.

    Source:trueend5
    Published:24 Feb 2006
    7.5
    High

    CVE-2006-0879

    Last Modified: 2 Aug 2013

    SQL injection vulnerability in the search tool in Noah's Classifieds 1.3 allows remote attackers to execute arbitrary SQL commands via unspecified attack vectors.

    Source:trueend5
    Published:24 Feb 2006
    5
    Medium

    CVE-2006-0877

    Last Modified: 5 Aug 2013

    Cross-site scripting vulnerability in Easy Forum 2.5 allows remote attackers to inject arbitrary web script or HTML via the image variable.

    Source:Aliaksandr Hartsuyeu
    Published:24 Feb 2006
    5
    Medium

    CVE-2006-0875

    Last Modified: 28 Nov 2016

    Cross-site scripting vulnerability in ratefile.php in RunCMS 1.3a5 allows remote attackers to inject arbitrary web script or HTML via the lid parameter.

    Source:Roozbeh Afrasiabi
    Published:24 Feb 2006
    6.4
    Medium

    CVE-2006-0871

    Last Modified: 19 Jan 2018

    Directory traversal vulnerability in the _setTemplate function in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to read and include arbitrary files via the mos_change_template parameter. NOTE: CVE-2006-1794 has been assigned to the SQL injection vector.

    Source:GulfTech Security
    Published:24 Feb 2006
    7.5
    High

    CVE-2006-0870

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in pages.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter. NOTE: version 2.3 was later reported to be vulnerable as well.

    Source:nukedx
    Published:23 Feb 2006
    6.4
    Medium

    CVE-2006-0869

    Last Modified: 19 Jan 2018

    Directory traversal vulnerability in the "remember me" feature in liveuser.php in PHP Extension and Application Repository (PEAR) LiveUser 0.16.8 and earlier allows remote attackers to determine file existence, and possibly delete arbitrary files with short pathnames or possibly read arbitrary files, via a .. (dot dot) in the store_id value of a cookie.

    Source:GulfTech Security
    Published:23 Feb 2006
    5
    Medium

    CVE-2006-0865

    Last Modified: 11 Nov 2016

    PunBB 1.2.10 and earlier allows remote attackers to cause a denial of service (resource consumption) by registering many user accounts quickly.

    Source:K4P0
    Published:23 Feb 2006