4.3
    Medium

    CVE-2006-0310

    Last Modified: 26 Jul 2013

    Cross-site scripting (XSS) vulnerability in aoblogger 2.3 allows remote attackers to inject arbitrary Javascript via a javascript URI in the BBcode url tag.

    Source:Aliaksandr Hartsuyeu
    Published:19 Jan 2006
    7.5
    High

    CVE-2006-0308

    Last Modified: 26 Sept 2016

    PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, module for PHP-Nuke allows remote attackers to execute arbitrary PHP code via a URL in the filnavn parameter.

    Source:Cold Zero
    Published:19 Jan 2006
    5
    Medium

    CVE-2006-0306

    Last Modified: 26 Jul 2013

    The DM Primer (dmprimer.exe) in the DM Deployment Common Component in Computer Associates (CA) BrightStor Mobile Backup r4.0, BrightStor ARCserve Backup for Laptops & Desktops r11.0, r11.1, r11.1 SP1, Unicenter Remote Control 6.0, 6.0 SP1, CA Desktop Protection Suite r2, CA Server Protection Suite r2, and CA Business Protection Suite r2 allows remote attackers to cause a denial of service (CPU consumption or application hang) via a large network packet, which causes a WSAEMESGSIZE error code that is not handled, leading to a thread exit.

    Source:Karma
    Published:19 Jan 2006
    7.5
    High

    CVE-2006-0304

    Last Modified: 5 Aug 2013

    Buffer overflow in Dual DHCP DNS Server 1.0 allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via the DHCP options field.

    Source:Luigi Auriemma
    Published:19 Jan 2006
    5.1
    Medium

    CVE-2006-0295

    Last Modified: 18 Jul 2016

    Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attackers to execute arbitrary code via the QueryInterface method of the built-in Location and Navigator objects, which leads to memory corruption.

    Source:H D Moore
    Published:2 Feb 2006
    10
    Critical

    CVE-2006-0287

    Last Modified: 16 Apr 2026

    Unspecified vulnerability in the Oracle HTTP Server component of Oracle Database Server 10.1.0.5 and Application Server 10.1.2.0.2 has unspecified impact and attack vectors, as identified by Oracle Vuln# OHS02.

    Source:Argeniss
    Published:18 Jan 2006
    4.3
    Medium

    CVE-2006-0254

    Last Modified: 25 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Geronimo 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) time parameter to cal2.jsp and (2) any invalid parameter, which causes an XSS when the log file is viewed by the Web-Access-Log viewer.

    Source:Oliver Karow
    Published:15 Jan 2006
    4.3
    Medium

    CVE-2006-0251

    Last Modified: 25 Jul 2013

    Cross-site scripting (XSS) vulnerability in fom.cgi in Faq-O-Matic 2.711 allows remote attackers to inject arbitrary web script or HTML via the (1) _duration, (2) file, and (3) cmd parameters.

    Source:Preddy
    Published:18 Jan 2006
    7.5
    High

    CVE-2006-0249

    Last Modified: 25 Jul 2013

    SQL injection vulnerability in viewcat.php in BitDamaged geoBlog MOD_1.0 allows remote attackers to execute arbitrary SQL commands, then steal credentials and upload files, via the cat parameter ($tmpCategory variable).

    Source:Aliaksandr Hartsuyeu
    Published:18 Jan 2006
    5
    Medium

    CVE-2006-0244

    Last Modified: 26 Jul 2013

    Directory traversal vulnerability in workspaces.php in phpXplorer 0.9.33 allows remote attackers to include arbitrary files via a .. (dot dot) and trailing null byte (%00) in the sShare parameter. NOTE: a followup post claims that this is not a vulnerability since the functionality of phpXplorer supports the upload of PHP files, which would not cross privilege boundaries since the PHP functionality would support read access outside the web root

    Source:Oriol Torrent Santiago
    Published:18 Jan 2006
    7.5
    High

    CVE-2006-0240

    Last Modified: 3 Jan 2017

    Multiple SQL injection vulnerabilities in Simple Blog 2.1 allow remote attackers to execute arbitrary SQL commands via the month parameter in an archives view operation and possibly certain other parameters in unspecified scripts.

    Source:Zinho
    Published:18 Jan 2006
    4.3
    Medium

    CVE-2006-0237

    Last Modified: 25 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in GTP iCommerce allows remote attackers to inject arbitrary web script or HTML via the (1) cat and (2) subcat parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

    Source:Preddy
    Published:18 Jan 2006
    7.5
    High

    CVE-2006-0235

    Last Modified: 25 Jul 2013

    SQL injection vulnerability in WhiteAlbum 2.5 allows remote attackers to execute arbitrary SQL commands via the dir parameter to pictures.php.

    Source:liz0
    Published:18 Jan 2006
    7.5
    High

    CVE-2006-0234

    Last Modified: 26 Jul 2013

    SQL injection vulnerability in index.php in microBlog 2.0 RC-10 allows remote attackers to execute arbitrary SQL commands via the (1) month and (2) year parameters.

    Source:Aliaksandr Hartsuyeu
    Published:18 Jan 2006
    10
    Critical

    CVE-2006-0230

    Last Modified: 16 Apr 2026

    Symantec Scan Engine 5.0.0.24, and possibly other versions before 5.1.0.7, uses a client-side check to verify a password, which allows remote attackers to gain administrator privileges via a modified client that sends certain XML requests.

    Source:Marc Bevand
    Published:25 Apr 2006
    4.3
    Medium

    CVE-2006-0222

    Last Modified: 25 Jul 2013

    Cross-site scripting (XSS) vulnerability in fullview.php in AlstraSoft Template Seller Pro allows remote attackers to inject arbitrary web script or HTML via the tempid parameter.

    Source:night_warrior771
    Published:16 Jan 2006
    4.3
    Medium

    CVE-2006-0217

    Last Modified: 25 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.

    Source:querkopf
    Published:16 Jan 2006
    7.5
    High

    CVE-2006-0214

    Last Modified: 16 Apr 2026

    Eval injection vulnerability in ezDatabase 2.0 and earlier allows remote attackers to execute arbitrary PHP code via the db_id parameter to visitorupload.php, as demonstrated using phpinfo and include function calls.

    Source:cijfer
    Published:15 Jan 2006
    4.3
    Medium

    CVE-2006-0211

    Last Modified: 25 Jul 2013

    Cross-site scripting (XSS) vulnerability in forgotPassword.asp in Helm Hosting Control Panel 3.2.8 and earlier allows remote attackers to inject arbitrary web script or HTML via the txtEmailAddress parameter.

    Source:M.Neset KABAKLI
    Published:14 Jan 2006
    4.3
    Medium

    CVE-2006-0210

    Last Modified: 24 Jul 2013

    Cross-site scripting (XSS) vulnerability in index.php in Interspire TrackPoint NX before 0.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter when using the Login page.

    Source:M.Neset KABAKLI
    Published:14 Jan 2006
    7.5
    High

    CVE-2006-0209

    Last Modified: 24 Jul 2013

    SQL injection vulnerability in general_functions.php in TankLogger 2.4 allows remote attackers to execute arbitrary SQL commands via the (1) livestock_id parameter to showInfo.php and (2) tank_id parameter, possibly to livestock.php.

    Source:Aliaksandr Hartsuyeu
    Published:14 Jan 2006
    7.5
    High

    CVE-2006-0206

    Last Modified: 29 Jun 2016

    Eval injection vulnerability in Light Weight Calendar (LWC) 1.0 (20040909) and earlier allows remote attackers to execute arbitrary PHP code via the date parameter in cal.php, which is included by index.php.

    Source:Hessam-x
    Published:13 Jan 2006
    7.5
    High

    CVE-2006-0199

    Last Modified: 14 Nov 2016

    SQL injection vulnerability in news.asp in Mini-Nuke CMS System 1.8.2 and earlier allows remote attackers to execute arbitrary SQL commands via the hid parameter.

    Source:DetMyl
    Published:13 Jan 2006
    4.3
    Medium

    CVE-2006-0198

    Last Modified: 24 Jul 2013

    Cross-site scripting (XSS) vulnerability in a certain module, possibly poll or Pool, for XOOPS allows remote attackers to inject arbitrary web script or HTML via JavaScript in the SRC attribute of an IMG element in a comment.

    Source:night_warrior771
    Published:13 Jan 2006
    4.3
    Medium

    CVE-2006-0194

    Last Modified: 24 Jul 2013

    Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.

    Source:M.Neset KABAKLI
    Published:13 Jan 2006
    7.5
    High

    CVE-2006-0189

    Last Modified: 16 Apr 2026

    Buffer overflow in eStara Softphone 3.0.1.14 through 3.0.1.46 allows remote attackers to execute arbitrary code via a long attribute (aka "a") field in the SDP data of a SIP packet on UDP port 5060.

    Source:ZwelL
    Published:13 Jan 2006
    5.1
    Medium

    CVE-2006-0187

    Last Modified: 24 Jul 2013

    By design, Microsoft Visual Studio 2005 automatically executes code in the Load event of a user-defined control (UserControl1_Load function), which allows user-assisted attackers to execute arbitrary code by tricking the user into opening a malicious Visual Studio project file.

    Source:anonymous
    Published:12 Jan 2006
    5
    Medium

    CVE-2006-0185

    Last Modified: 24 Jul 2013

    Multiple cross-site scripting vulnerabilities in the (1) Pool or (2) News Modules in Php-Nuke allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of an IMG tag.

    Source:night_warrior771
    Published:12 Jan 2006
    5
    Medium

    CVE-2006-0179

    Last Modified: 16 Apr 2026

    The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN packets (syn flood) to arbitrary ports, as demonstrated to port 80.

    Source:kokanin
    Published:11 Jan 2006
    7.2
    High

    CVE-2006-0177

    Last Modified: 24 Jul 2013

    Multiple buffer overflows in Cray UNICOS 9.0.2.2 might allow local users to gain privileges by (1) invoking /usr/bin/script with a long command line argument or (2) setting the -c option of /etc/nu to the name of a file containing a long line.

    Source:Micheal Turner
    Published:11 Jan 2006
    7.2
    High

    CVE-2006-0176

    Last Modified: 13 Jun 2016

    Buffer overflow in certain functions in src/fileio.c and src/unix/fileio.c in xmame before 11 January 2006 may allow local users to gain privileges via a long (1) -lang, (2) -ctrlr, (3) -pb, or (4) -rec argument on many operating systems, and via a long (5) -jdev argument on Ubuntu Linux.

    Source:xwings
    Published:11 Jan 2006
    4.3
    Medium

    CVE-2006-0175

    Last Modified: 24 Jul 2013

    Cross-site scripting (XSS) vulnerability in search_form.asp in Web Wiz Forums 6.34 allows remote attackers to inject arbitrary web script or HTML via the search parameter.

    Source:nukedx
    Published:11 Jan 2006
    4
    Medium

    CVE-2006-0174

    Last Modified: 24 Jul 2013

    Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to obtain sensitive information (intranet IP addresses and enumerations of valid parameter values) via a direct request to hc, which reveals the information in an error message or a cookie.

    Source:Luca Carettoni
    Published:11 Jan 2006
    4
    Medium

    CVE-2006-0173

    Last Modified: 24 Jul 2013

    Hummingbird Collaboration (aka Hummingbird Enterprise Collaboration) 5.21 and earlier allows remote attackers to misrepresent the type and name of a file via modified doc_ext and id parameters, which might trick a user into downloading dangerous or unexpected content.

    Source:Luca Carettoni
    Published:11 Jan 2006
    7.5
    High

    CVE-2006-0171

    Last Modified: 24 Jul 2013

    PHP remote file include vulnerability in index.php in OrjinWeb E-commerce allows remote attackers to execute arbitrary code via a URL in the page parameter. NOTE: it is not clear, but OrjinWeb might be an application service, in which case it should not be included in CVE.

    Source:serxwebun
    Published:11 Jan 2006
    7.5
    High

    CVE-2006-0167

    Last Modified: 24 Jul 2013

    SQL injection vulnerability in MyPhPim 01.05 allows remote attackers to execute arbitrary SQL commands via the (1) cal_id parameter in calendar.php3 and the (2) password field on the login page.

    Source:Aliaksandr Hartsuyeu
    Published:11 Jan 2006
    7.5
    High

    CVE-2006-0164

    Last Modified: 27 Sept 2016

    phgstats.inc.php in phgstats before 0.5.1, if register_globals is enabled, allows remote attackers to include arbitrary files and execute arbitrary PHP code by modifying the PHGDIR variable.

    Source:bd0rk
    Published:11 Jan 2006
    7.5
    High

    CVE-2006-0163

    Last Modified: 24 Jul 2013

    SQL injection vulnerability in the search module (modules/Search/index.php) of PHPNuke EV 7.7 -R1 allows remote attackers to execute arbitrary SQL commands via the query parameter, which is used by the search field. NOTE: This is a different vulnerability than CVE-2005-3792.

    Source:Lostmon
    Published:11 Jan 2006
    7.5
    High

    CVE-2006-0160

    Last Modified: 23 Jul 2013

    SQL injection vulnerability in add_post.php3 in Venom Board 1.22 allows remote attackers to execute arbitrary SQL commands via the (1) parent, (2) root, and (3) topic_id parameters to post.php3.

    Source:Aliaksandr Hartsuyeu
    Published:10 Jan 2006
    5
    Medium

    CVE-2006-0157

    Last Modified: 16 Apr 2026

    settings.php in Reamday Enterprises Magic News Plus 1.0.3 allows remote attackers to change the administrator password via a change action that specifies identical values for the passwd and admin_password parameters, then declares the new password string in the new_passwd and confirm_passwd parameters.

    Source:cijfer
    Published:10 Jan 2006
    7.5
    High

    CVE-2006-0154

    Last Modified: 7 Dec 2016

    SQL injection vulnerability in showthread.php in 427BB 2.2 and 2.2.1 allows remote attackers to execute arbitrary SQL commands via the ForumID parameter.

    Source:Aliaksandr Hartsuyeu
    Published:10 Jan 2006
    7.5
    High

    CVE-2006-0153

    Last Modified: 7 Dec 2016

    427BB 2.2 and 2.2.1 verifies authentication credentials based on the username, authenticated, and usertype cookies, which allows remote attackers to bypass authentication by using a valid username and usertype and setting the authenticated cookie.

    Source:Aliaksandr Hartsuyeu
    Published:10 Jan 2006
    7.5
    High

    CVE-2006-0147

    Last Modified: 16 Apr 2026

    Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PhpOpenChat, possibly (7) MAXdev MD-Pro, and (8) Simplog, allows remote attackers to execute arbitrary PHP functions via the do parameter, which is saved in a variable that is then executed as a function, as demonstrated using phpinfo.

    Source:rgod
    Published:9 Jan 2006
    7.5
    High

    CVE-2006-0146

    Last Modified: 16 Apr 2026

    The server.php test script in ADOdb for PHP before 4.70, as used in multiple products including (1) Mantis, (2) PostNuke, (3) Moodle, (4) Cacti, (5) Xaraya, (6) PHPOpenChat, (7) MAXdev MD-Pro, and (8) MediaBeez, when the MySQL root password is empty, allows remote attackers to execute arbitrary SQL commands via the sql parameter.

    Source:rgod
    Published:9 Jan 2006
    7.5
    High

    CVE-2006-0143

    Last Modified: 5 Aug 2013

    Microsoft Windows Graphics Rendering Engine (GRE) allows remote attackers to corrupt memory and cause a denial of service (crash) via a WMF file containing (1) ExtCreateRegion or (2) ExtEscape function calls with arguments with inconsistent lengths.

    Source:cocoruder
    Published:9 Jan 2006
    5
    Medium

    CVE-2006-0138

    Last Modified: 27 Jul 2015

    aMSN (aka Alvaro's Messenger) allows remote attackers to cause a denial of service (client hang and termination of client's instant-messaging session) by repeatedly sending crafted data to the default file-transfer port (TCP 6891).

    Source:Braulio Miguel Suarez Urquijo
    Published:9 Jan 2006
    7.5
    High

    CVE-2006-0137

    Last Modified: 22 Jul 2013

    SQL injection vulnerability in linkcategory.php in Phanatic Softwares Chimera Web Portal System 0.2 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Aliaksandr Hartsuyeu
    Published:9 Jan 2006
    4.3
    Medium

    CVE-2006-0136

    Last Modified: 22 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.

    Source:Aliaksandr Hartsuyeu
    Published:9 Jan 2006
    7.5
    High

    CVE-2006-0135

    Last Modified: 23 Jul 2013

    SQL injection vulnerability in login.php in TheWebForum (twf) 1.2.1 allows remote attackers to execute arbitrary SQL commands and bypass login authentication via the username parameter (aka the u variable).

    Source:Aliaksandr Hartsuyeu
    Published:9 Jan 2006
    3.6
    Low

    CVE-2006-0133

    Last Modified: 22 Jul 2013

    Multiple directory traversal vulnerabilities in AIX 5.3 ML03 allow local users to determine the existence of files and read partial contents of certain files via a .. (dot dot) in the argument to (1) getCommand.new (aka getCommand) and (2) getShell, a different vulnerability than CVE-2005-4273.

    Source:xfocus
    Published:9 Jan 2006