LiveActive security incident?Get immediate response
CVE archive

February 2006

Browse CVE records published in February 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 591 matching CVEs · Page 8 of 12.

Unknown · CVSS Not scored

CVE-2006-0683: Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch an...

Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.

Published Feb 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0708: Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary c...

Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) an m3u file containing a long URL ending in .wma, (2) a pls file containing a File1 field with a long URL ending in .wma, or (3) an m3u file with a long filename, variants of CVE-2005-3188 and CVE-2006-0476.

Published Feb 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0704: iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attacker...

iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain sensitive information via a URL that calls a non-existent .aspx script in the integrator/apps directory, which results in an error message that displays the installation path, web server name, IP, and port, session cookie information, and the IIS system username.

Published Feb 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0705: Format string vulnerability in a logging function as used by various SFTP servers, including (1) Attachmate...

Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflection for Secure IT UNIX Server before 6.0.0.9, (2) Reflection for Secure IT Windows Server before 6.0 build 38, (3) F-Secure SSH Server for Windows before 5.3 build 35, (4) F-Secure SSH Server for UNIX 3.0 through 5.0.8, (5) SSH Tectia Server 4.3.6 and earlier and 4.4.0, and (6) SSH Shell Server 3.2.9 and earlier, allows remote authenticated users to execute arbitrary commands via unspecified vectors, involving crafted filenames and the stat command.

Published Feb 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0657: Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated...

Cross-site scripting (XSS) vulnerability in Softcomplex PHP Event Calendar 1.5 allows remote authenticated users to inject arbitrary web script or HTML, and corrupt data, via the (1) username and (2) password parameters, which are not sanitized before being written to users.php. NOTE: while this issue was originally reported as XSS, the primary issue might be direct static code injection with resultant XSS.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0664: Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote atta...

Cross-site scripting (XSS) vulnerability in config_defaults_inc.php in Mantis before 1.0 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. An original vendor bug report is referenced, but not accessible to the general public.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0650: Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in...

Cross-site scripting (XSS) vulnerability in cpaint2.inc.php in the CPAINT library before 2.0.3, as used in multiple scripts, allows remote attackers to inject arbitrary web script or HTML via the cpaint_response_type parameter, which is displayed in a resulting error message, as demonstrated using a hex-encoded IFRAME tag.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0660: Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) re...

Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary files or trigger an error message path disclosure via ".." or invalid names in the archive parameter to index.php, or (2) include arbitrary files via the template parameter to show_archives.php.

Published Feb 13, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-0663: Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remot...

Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers to inject arbitrary web script or HTML via (1) an email subject; (2) an encoded javascript URI, as demonstrated using "java
script:"; or (3) when the Domino Web Access ActiveX control is not installed, via an email attachment filename.

Published Feb 13, 2006 · Updated Aug 7, 2024