4.3
    Medium

    CVE-2006-0496

    Last Modified: 28 Jul 2013

    Cross-site scripting (XSS) vulnerability in Mozilla 1.7.12 and possibly earlier, Mozilla Firefox 1.0.7 and possibly earlier, and Netscape 8.1 and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the -moz-binding (Cascading Style Sheets) CSS property, which does not require that the style sheet have the same origin as the web page, as demonstrated by the compromise of a large number of LiveJournal accounts.

    Source:Chris Thomas
    Published:1 Feb 2006
    7.5
    High

    CVE-2006-0491

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Aliaksandr Hartsuyeu
    Published:1 Feb 2006
    4.3
    Medium

    CVE-2006-0480

    Last Modified: 28 Jul 2013

    Cross-site scripting (XSS) vulnerability in the Articles module in sPaiz-Nuke allows remote attackers to inject arbitrary web script or HTML via the query parameter in the search file.

    Source:night_warrior771
    Published:31 Jan 2006
    4.3
    Medium

    CVE-2006-0479

    Last Modified: 28 Jul 2013

    pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms that deregister global variables by setting both a GPC variable and a GLOBALS[] variable with the same name, which causes PmWiki to unset the GLOBALS[] variable but not the GPC variable, which creates resultant vulnerabilities such as remote file inclusion and cross-site scripting (XSS).

    Source:aScii
    Published:31 Jan 2006
    7.5
    High

    CVE-2006-0478

    Last Modified: 16 Apr 2026

    CRE Loaded 6.15 allows remote attackers to perform privileged actions, including uploading and creating arbitrary files, via a direct request to files.php. NOTE: the vendor states "The initial announcement of this risk was made on our website... and it included a patch which will close the vulnerability on all known 6.0x and 6.1x releases. We strongly encourage users of CRE Loaded 6.x, osCMax, and other users of osCommerce who have installed HTMLArea based WYSIWYG editors and Admin Access with Levels to modify thier installations at the earliest possible moment."

    Source:kaneda
    Published:31 Jan 2006
    7.6
    High

    CVE-2006-0476

    Last Modified: 10 Mar 2011

    Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with a long file name (File1 field).

    Source:Metasploit
    Published:31 Jan 2006
    4.3
    Medium

    CVE-2006-0473

    Last Modified: 28 Jul 2013

    Cross-site scripting (XSS) vulnerability in the bbcode function in weblog.php in my little homepage my little weblog, as last modified in April 2004, allows remote attackers to inject arbitrary Javascript via a javascript URI in BBcode link tags.

    Source:Aliaksandr Hartsuyeu
    Published:31 Jan 2006
    4.3
    Medium

    CVE-2006-0470

    Last Modified: 28 Jul 2013

    Cross-site scripting (XSS) vulnerability in search.php in MyBulletinBoard (MyBB) 1.02 allows remote attackers to inject arbitrary web script or HTML via the (1) sortby and (2) sortordr parameters, which are not properly handled in a redirection.

    Source:imei
    Published:31 Jan 2006
    4.3
    Medium

    CVE-2006-0469

    Last Modified: 20 Aug 2012

    Cross-site scripting (XSS) vulnerability in UebiMiau 2.7.9, and possibly earlier versions, allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the SRC attribute of an IMG tag.

    Source:Shai rod
    Published:30 Jan 2006
    7.5
    High

    CVE-2006-0468

    Last Modified: 28 Jul 2013

    CommuniGate Pro Core Server before 5.0.7 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via LDAP messages with negative BER lengths, and possibly other vectors, as demonstrated by the ProtoVer LDAP test suite.

    Source:Evgeny Legerov
    Published:30 Jan 2006
    7.5
    High

    CVE-2006-0462

    Last Modified: 28 Jul 2013

    SQL injection vulnerability in comentarios.php in AndoNET Blog 2004.09.02 allows remote attackers to execute arbitrary SQL commands via the entrada parameter.

    Source:Aliaksandr Hartsuyeu
    Published:27 Jan 2006
    4.3
    Medium

    CVE-2006-0461

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in core.input.php in ExpressionEngine 1.4.1 allows remote attackers to inject arbitrary web script or HTML via HTTP_REFERER (referer).

    Source:Aliaksandr Hartsuyeu
    Published:27 Jan 2006
    7.5
    High

    CVE-2006-0460

    Last Modified: 30 Jun 2016

    Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error messages.

    Source:esca zoo
    Published:17 Feb 2006
    4.6
    Medium

    CVE-2006-0455

    Last Modified: 31 Jul 2013

    gpgv in GnuPG before 1.4.2.1, when using unattended signature verification, returns a 0 exit code in certain cases even when the detached signature file does not carry a signature, which could cause programs that use gpgv to assume that the signature verification has succeeded. Note: this also occurs when running the equivalent command "gpg --verify".

    Source:taviso
    Published:15 Feb 2006
    5
    Medium

    CVE-2006-0450

    Last Modified: 16 Apr 2026

    phpBB 2.0.19 and earlier allows remote attackers to cause a denial of service (application crash) by (1) registering many users through profile.php or (2) using search.php to search in a certain way that confuses the database.

    Published:27 Jan 2006
    6.8
    Medium

    CVE-2006-0444

    Last Modified: 5 Jan 2017

    SQL injection vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.1 allows remote attackers to execute arbitrary SQL commands via the (1) par parameter in the post function on the forum page and possibly the (2) poll_id parameter on the poll page. NOTE: the poll_id vector can also allow resultant cross-site scripting (XSS) from an unquoted error message for invalid SQL syntax.

    Source:matrix_killer
    Published:26 Jan 2006
    4.3
    Medium

    CVE-2006-0443

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in archive.php in CheesyBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) realname and (2) comment parameters, or (3) via a javascript URI in the url parameter, when adding a comment.

    Source:Aliaksandr Hartsuyeu
    Published:26 Jan 2006
    4.3
    Medium

    CVE-2006-0442

    Last Modified: 27 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in usercp.php in MyBulletinBoard (MyBB) 1.02 allow remote attackers to inject arbitrary web script or HTML via the (1) notepad parameter in a notepad action and (2) signature parameter in an editsig action. NOTE: These are different attack vectors, and probably a different vulnerability, than CVE-2006-0218 and CVE-2006-0219.

    Source:Roozbeh Afrasiabi
    Published:26 Jan 2006
    7.5
    High

    CVE-2006-0441

    Last Modified: 1 Nov 2016

    Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER command, which triggers the overflow when the log is viewed.

    Source:Marsu
    Published:26 Jan 2006
    7.5
    High

    CVE-2006-0418

    Last Modified: 27 Jul 2013

    Eval injection vulnerability in 123 Flash Chat Server 5.0 and 5.1 allows attackers to execute arbitrary code via a crafted username.

    Source:Jesus Olmos Gonzalez
    Published:25 Jan 2006
    7.5
    High

    CVE-2006-0417

    Last Modified: 27 Jul 2013

    SQL injection vulnerability in login.php in miniBloggie 1.0 and earlier, when gpc_magic_quotes is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameters.

    Source:Aliaksandr Hartsuyeu
    Published:25 Jan 2006
    4.3
    Medium

    CVE-2006-0415

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in SleeperChat 0.3f and earlier allows remote attackers to inject arbitrary web script or HTML via the pseudo parameter.

    Source:hackologie
    Published:25 Jan 2006
    7.5
    High

    CVE-2006-0413

    Last Modified: 27 Jul 2013

    Multiple SQL injection vulnerabilities in index.php in NewsPHP allow remote attackers to execute arbitrary SQL commands via the (1) discuss, (2) tim, (3) id, (4) last, and (5) limit parameter.

    Source:SAUDI
    Published:25 Jan 2006
    4.3
    Medium

    CVE-2006-0409

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in Pixelpost Photoblog 1.4.3 allows remote attackers to inject arbitrary web script or HTML via the "Add Comment" field in a comment popup.

    Source:Aliaksandr Hartsuyeu
    Published:25 Jan 2006
    4.3
    Medium

    CVE-2006-0407

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.

    Source:Roozbeh Afrasiabi
    Published:25 Jan 2006
    5.1
    Medium

    CVE-2006-0396

    Last Modified: 16 Apr 2026

    Buffer overflow in Mail in Apple Mac OS X 10.4 up to 10.4.5, when patched with Security Update 2006-001, allows remote attackers to execute arbitrary code via a long Real Name value in an e-mail attachment sent in AppleDouble format, which triggers the overflow when the user double-clicks on an attachment.

    Source:Kevin Finisterre
    Published:14 Mar 2006
    5.1
    Medium

    CVE-2006-0395

    Last Modified: 27 Oct 2016

    The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an unsafe type, which allows user-assisted remote attackers to execute arbitrary code via crafted file types.

    Source:Metasploit
    Published:5 Aug 2006
    7.5
    High

    CVE-2006-0372

    Last Modified: 27 Jul 2013

    Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username or (2) blogphp_password parameter in a cookie.

    Source:imei
    Published:22 Jan 2006
    4.3
    Medium

    CVE-2006-0366

    Last Modified: 26 Jul 2013

    Cross-site scripting (XSS) vulnerability in Phpclanwebsite (aka PCW) allows remote attackers to inject arbitrary web script or HTML via a javascript URI in a BBCode img tag.

    Source:kurdish hackers team
    Published:22 Jan 2006
    4.3
    Medium

    CVE-2006-0361

    Last Modified: 25 Jul 2013

    Cross-site scripting (XSS) vulnerability in addcomment.php in Bit 5 Blog 8.01 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in an <a> tag in the comment parameter, which strips most tags but not <a>.

    Source:Aliaksandr Hartsuyeu
    Published:22 Jan 2006
    7.5
    High

    CVE-2006-0359

    Last Modified: 25 Jul 2013

    Buffer overflow in CounterPath eyeBeam SIP Softphone allows remote attackers to (1) cause a denial of service (device crash) via SIP INVITE commands with a long header field name sent during startup and (2) cause a denial of service (device hang or crash) via SIP INVITE commands with a long header field name sent during a call.

    Source:ZwelL
    Published:22 Jan 2006
    7.5
    High

    CVE-2006-0358

    Last Modified: 23 Dec 2016

    Multiple SQL injection vulnerabilities in PowerPortal, possibly 1.1 beta through 1.3, allow remote attackers to execute arbitrary SQL commands via the search parameter in (1) index.php and (2) search.php. NOTE: This issue might overlap CVE-2004-0663.2.

    Source:night_warrior771
    Published:22 Jan 2006
    5
    Medium

    CVE-2006-0357

    Last Modified: 16 Apr 2026

    Grant Averett Cerberus FTP Server 2.32, and possibly earlier versions, allows remote attackers to cause an unspecified denial of service via a long string that does not contain a valid FTP command.

    Source:pi3ch
    Published:22 Jan 2006
    5
    Medium

    CVE-2006-0355

    Last Modified: 21 Jun 2016

    Helmsman Research (aka CoolUtils) HomeFtp 1.1 allows remote attackers to cause an unspecified denial of service via a long USER command combined with a long PASS command and an NLST command.

    Source:pi3ch
    Published:22 Jan 2006
    5.5
    Medium

    CVE-2006-0354

    Last Modified: 16 Apr 2026

    Cisco IOS before 12.3-7-JA2 on Aironet Wireless Access Points (WAP) allows remote authenticated users to cause a denial of service (termination of packet passing or termination of client connections) by sending the management interface a large number of spoofed ARP packets, which creates a large ARP table that exhausts memory, aka Bug ID CSCsc16644.

    Source:Pasv
    Published:22 Jan 2006
    4.3
    Medium

    CVE-2006-0350

    Last Modified: 11 Jan 2017

    Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.

    Published:21 Jan 2006
    7.5
    High

    CVE-2006-0349

    Last Modified: 11 Jan 2017

    SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.

    Published:21 Jan 2006
    7.5
    High

    CVE-2006-0345

    Last Modified: 26 Jul 2013

    Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.php issue is already covered by CVE-2005-4058.

    Source:Aliaksandr Hartsuyeu
    Published:21 Jan 2006
    4.3
    Medium

    CVE-2006-0341

    Last Modified: 27 Jul 2013

    Cross-site scripting (XSS) vulnerability in WCONSOLE.DLL in Rockliffe MailSite 5.x and 6.1.22 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string.

    Source:OS2A BTO
    Published:6 Jan 2006
    4.6
    Medium

    CVE-2006-0331

    Last Modified: 21 Jun 2016

    Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

    Source:rod hedor
    Published:21 Jan 2006
    5
    Medium

    CVE-2006-0328

    Last Modified: 29 Sept 2016

    Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.

    Source:Critical Security
    Published:21 Jan 2006
    7.5
    High

    CVE-2006-0324

    Last Modified: 27 Jul 2013

    SQL injection vulnerability in WebspotBlogging 3.0 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter to login.php.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006
    9.3
    Critical

    CVE-2006-0323

    Last Modified: 10 Aug 2013

    Buffer overflow in swfformat.dll in multiple RealNetworks products and versions including RealPlayer 10.x, RealOne Player, Rhapsody 3, and Helix Player allows remote attackers to execute arbitrary code via a crafted SWF (Flash) file with (1) a size value that is less than the actual size, or (2) other unspecified manipulations.

    Source:Federico L. Bossi Bonin
    Published:22 Mar 2006
    7.5
    High

    CVE-2006-0320

    Last Modified: 25 Jul 2013

    SQL injection vulnerability in admin/processlogin.php in Bit 5 Blog 8.01 allows remote attackers to execute arbitrary SQL commands and bypass authentication via the (1) username and (2) password parameter.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006
    5
    Medium

    CVE-2006-0319

    Last Modified: 16 Apr 2026

    Directory traversal vulnerability in the FTP server (port 22003/tcp) in Farmers WIFE 4.4 SP1 allows remote attackers to create arbitrary files via ".." (dot dot) sequences in a (1) PUT, (2) SIZE, and possibly other commands.

    Source:kokanin
    Published:19 Jan 2006
    7.5
    High

    CVE-2006-0318

    Last Modified: 9 Dec 2016

    SQL injection vulnerability in index.php in BlogPHP 1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands and bypass authentication via the username parameter in a login action.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006
    4.3
    Medium

    CVE-2006-0317

    Last Modified: 26 Jul 2013

    Cross-site scripting (XSS) vulnerability in rkrt_stats.php in RedKernel Referrer Tracker 1.1.0-3 allows remote attackers to inject arbitrary web script or HTML via a query string value as a GET, which is stored in the $QUERY_STRING variable. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

    Source:Preddy
    Published:19 Jan 2006
    5.8
    Medium

    CVE-2006-0315

    Last Modified: 25 Jul 2013

    index.php in EZDatabase before 2.1.2 does not properly cleanse the p parameter before constructing and including a .php filename, which allows remote attackers to conduct directory traversal attacks, and produces resultant cross-site scripting (XSS) and path disclosure.

    Source:Josh Zlatin-Amishav
    Published:19 Jan 2006
    5
    Medium

    CVE-2006-0312

    Last Modified: 26 Jul 2013

    create.php in aoblogger 2.3 allows remote attackers to bypass authentication and create new blog entries by setting the uza parameter to 1.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006
    7.5
    High

    CVE-2006-0311

    Last Modified: 26 Jul 2013

    SQL injection vulnerability in login.php in aoblogger 2.3 allows remote attackers to execute arbitrary SQL commands via the username parameter.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006