LiveActive security incident?Get immediate response
CVE archive

May 2006

Browse CVE records published in May 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 594 matching CVEs · Page 4 of 12.

Unknown · CVSS Not scored

CVE-2006-2553: Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to injec...

Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. This issue appears to be independent from a different issue that involves the same vector.

Published May 24, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2500: Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote a...

Cross-site scripting (XSS) vulnerability in add_news.asp in CodeAvalanche News (CANews) 1.2 allows remote attackers to inject arbitrary web script or HTML via the Headline field. NOTE: if this issue is limited to administrators, and if it is expected behavior for administrators to be able to generate HTML, then this is not a vulnerability.

Published May 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2532: stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via...

stats.php in Destiney Rated Images Script 0.5.0 allows remote attackers to obtain the installation path via an invalid s parameter, which displays the path in an error message. NOTE: this issue was originally claimed to be SQL injection, but CVE analysis shows that the problem is related to an invalid value that prevents some variables from being set.

Published May 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2490: Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5....

Multiple cross-site scripting (XSS) vulnerabilities in Mobotix IP Network Cameras M1 1.9.4.7 and M10 2.0.5.2, and other versions before 2.2.3.18 for M10/D10 and 3.0.3.31 for M22, allow remote attackers to inject arbitrary web script or HTML via URL-encoded values in (1) the query string to help/help, (2) the get_image_info_abspath parameter to control/eventplayer, and (3) the source_ip parameter to events.tar.

Published May 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2473: Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbit...

Cross-site scripting (XSS) vulnerability in ow.asp in OpenWiki 0.78 allows remote attackers to inject arbitrary web script or HTML via the p parameter. NOTE: this issue has been disputed by the vendor and a third party who is affiliated with the product. The vendor states "You cannot insert code in a wikipage or via URL parameters as they are all escaped before usage, so nothing can be compromised at other sites.

Published May 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2516: mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to ov...

mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite variables such as $xoopsOption['nocommon'] and conduct directory traversal attacks or include PHP files via (1) xoopsConfig[language] to misc.php or (2) xoopsConfig[theme_set] to index.php, as demonstrated by injecting PHP sequences into a log file.

Published May 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2544: Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote...

Multiple SQL injection vulnerabilities in Xtreme Topsites 1.1, with magic_quotes_gpc disabled, allow remote attackers to execute arbitrary SQL commands via the (1) searchthis parameter in lostid.php and (2) id parameter in stats.php. NOTE: the provenance of this information is unknown; portions of the details are obtained from third party information.

Published May 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2535: index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an inv...

index.php in Destiney Links Script 2.1.2 allows remote attackers to obtain the installation path via an invalid show parameter referencing a non-existent file, which reveals the path in the resulting error message. NOTE: this issue might be resultant from a more serious issue such as directory traversal.

Published May 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2545: Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject...

Multiple cross-site scripting (XSS) vulnerabilities in Xtreme Topsites 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) id parameter in stats.php and (2) unspecified inputs in lostid.php, probably the searchthis parameter. NOTE: one or more of these vectors might be resultant from SQL injection.

Published May 23, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2444: The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attack...

The snmp_trap_decode function in the SNMP NAT helper for Linux kernel before 2.6.16.18 allows remote attackers to cause a denial of service (crash) via unspecified remote attack vectors that cause failures in snmp_trap_decode that trigger (1) frees of random memory or (2) frees of previously-freed memory (double-free) by snmp_trap_decode as well as its calling function, as demonstrated via certain test cases of the PROTOS SNMP test suite.

Published May 25, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2538: IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of...

IE Tab 1.0.9 plugin for Mozilla Firefox 1.5.0.3 allows remote user-assisted attackers to cause a denial of service (application crash), possibly due to a null dereference, via certain Javascript, as demonstrated using a url parameter to the content/reloaded.html page in a chrome:// URI. Some third-party researchers claim that they are unable to reproduce this vulnerability.

Published May 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2537: Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 an...

Multiple format string vulnerabilities in (a) OpenBOR 2.0046 and earlier, (b) Beats of Rage (BOR) 1.0029 and earlier, and (c) Horizontal Shooter BOR (HOR) 2.0000 and earlier allow remote attackers to execute code via format string specifiers in configurations used in various mod files, as demonstrated by the (1) music identifier in data/scenes/intro.txt, which is not properly handled in the update function, and (2) background identifier in data/easy/1aeasy.txt, which is not properly handled in the shutdown function.

Published May 22, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2428: add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with ar...

add.asp in DUware DUbanner 3.1 allows remote attackers to execute arbitrary code by uploading files with arbitrary extensions, such as ASP files, probably due to client-side enforcement that can be bypassed. NOTE: some of these details are obtained from third party information, since the raw source is vague.

Published May 17, 2006 · Updated Aug 7, 2024