LiveActive security incident?Get immediate response
CVE archive

May 2006

Browse CVE records published in May 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 594 matching CVEs · Page 7 of 12.

Unknown · CVSS Not scored

CVE-2006-2364: Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier a...

Cross-site scripting (XSS) vulnerability in the validation feature in Macromedia ColdFusion 5 and earlier allows remote attackers to inject arbitrary web script or HTML via a "_required" field when the associated normal field is missing or empty, which is not sanitized before being presented in an error message.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2369: RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remot...

RealVNC 4.1.1, and other products that use RealVNC such as AdderLink IP and Cisco CallManager, allows remote attackers to bypass authentication via a request in which the client specifies an insecure security type such as "Type 1 - None", which is accepted even if it is not offered by the server, as originally demonstrated using a long password.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2358: Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attacke...

Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) the search parameter and (2) unspecified fields related to e-mail alerts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2351: Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Profe...

Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via the (1) sDeviceView or (2) nDeviceID parameter to (a) NmConsole/Navigation.asp or (3) sHostname parameter to (b) NmConsole/ToolResults.asp.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2354: NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium ge...

NmConsole/Login.asp in Ipswitch WhatsUp Professional 2006 and Ipswitch WhatsUp Professional 2006 Premium generates different error messages in a way that allows remote attackers to enumerate valid usernames. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2349: E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, an...

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to upload or modify arbitrary files, and execute arbitrary code, via a direct request to (1) common/html_editor/image_browser.upload.html, (2) common/html_editor/image_browser.html, or (3) common/html_editor/html_editor.html. NOTE: this can also be used for cross-site scripting (XSS) attacks by uploading cascading style sheet (.CSS) files.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2352: Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Profe...

Multiple cross-site scripting (XSS) vulnerabilities in IPswitch WhatsUp Professional 2006 and WhatsUp Professional 2006 Premium allow remote attackers to inject arbitrary web script or HTML via unknown vectors in (1) NmConsole/Tools.asp and (2) NmConsole/DeviceSelection.asp. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published May 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2347: E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web serv...

E-Business Designer (eBD) 3.1.4 and earlier allows remote attackers to obtain the full path of the web server via "'" characters, and possibly other invalid values, in (1) the id parameter to form_grupo.html, or requests to the (2) archivos/ and (3) files/ directories. NOTE: this issue might be resultant from SQL injection.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2320: Multiple SQL injection vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers...

Multiple SQL injection vulnerabilities in Ideal Science Ideal BB 1.5.4a and earlier allow remote attackers to execute arbitrary SQL commands via multiple unspecified vectors related to stored procedure calls. NOTE: due to lack of details from the researcher, it is not clear whether this overlaps CVE-2004-2209.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2335: Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows r...

Jelsoft vBulletin accepts uploads of Cascading Style Sheets (CSS) and processes them in a way that allows remote authenticated administrators to gain shell access by uploading a CSS file that contains PHP code, then selecting the file via the style chooser, which causes the PHP code to be executed. NOTE: the vendor was unable to reproduce this issue in 3.5.x. NOTE: this issue might be due to direct static code injection.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2331: Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and e...

Multiple directory traversal vulnerabilities in PHP-Fusion 6.00.306 allow remote attackers to include and execute arbitrary local files via (1) a .. (dot dot) in the settings[locale] parameter in infusions/last_seen_users_panel/last_seen_users_panel.php, and (2) a .. (dot dot) in the localeset parameter in setup.php. NOTE: the vendor states that this issue might exist due to problems in third party local files.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2286: Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier...

Multiple PHP remote file inclusion vulnerabilities in claro_init_global.inc.php in Dokeos 1.6.3 and earlier, and Dokeos community release 2.0.3, allow remote attackers to execute arbitrary PHP code via a URL in the (1) rootSys and (2) clarolineRepositorySys parameters, and possibly the (3) lang_path, (4) extAuthSource, (5) thisAuthSource, (6) main_configuration_file_path, (7) phpDigIncCn, and (8) drs parameters to (a) testheaderpage.php and (b) resourcelinker.inc.php.

Published May 9, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2326: Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script al...

Directory traversal vulnerability in index.php in OnlyScript.info Online Universal Payment System Script allows remote attackers to read arbitrary files via directory traversal sequences in the read parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2255: Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers...

Multiple SQL injection vulnerabilities in Creative Community Portal 1.1 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to (a) ArticleView.php, (2) forum_id parameter to (b) DiscView.php or (c) Discussions.php, (3) event_id parameter to (d) EventView.php, (4) AddVote and (5) answer_id parameter to (e) PollResults.php, or (7) mid parameter to (f) DiscReply.php.

Published May 9, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2330: PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authe...

PHP-Fusion 6.00.306 and earlier, running under Apache HTTP Server 1.3.27 and PHP 4.3.3, allows remote authenticated users to upload files of arbitrary types using a filename that contains two or more extensions that ends in an assumed-valid extension such as .gif, which bypasses the validation, as demonstrated by uploading then executing an avatar file that ends in ".php.gif" and contains PHP code in EXIF metadata.

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2315: PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote att...

PHP remote file inclusion vulnerability in session.inc.php in ISPConfig 2.2.2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the go_info[server][classes_root] parameter. NOTE: the vendor has disputed this vulnerability, saying that session.inc.php is not under the web root in version 2.2, and register_globals is not enabled

Published May 12, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2314: PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier ve...

PostgreSQL 8.1.x before 8.1.4, 8.0.x before 8.0.8, 7.4.x before 7.4.13, 7.3.x before 7.3.15, and earlier versions allows context-dependent attackers to bypass SQL injection protection methods in applications that use multibyte encodings that allow the "\" (backslash) byte 0x5c to be the trailing byte of a multibyte character, such as SJIS, BIG5, GBK, GB18030, and UHC, which cannot be handled correctly by a client that does not understand multibyte encodings, aka a second variant of "Encoding-Based SQL Injection." NOTE: it could be argued that this is a class of issue related to interaction errors between the client and PostgreSQL, but a CVE has been assigned since PostgreSQL is treating this as a preventative measure against this class of problem.

Published May 24, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-2345: Cross-site scripting (XSS) vulnerability in inc/elementz.php in AliPAGER 1.5 allows remote attackers to inj...

Cross-site scripting (XSS) vulnerability in inc/elementz.php in AliPAGER 1.5 allows remote attackers to inject arbitrary web script or HTML via the ubild parameter. NOTE: the provenance of this information is unknown; the details are obtained from third party information. NOTE: this issue might be resultant from SQL injection.

Published May 12, 2006 · Updated Aug 7, 2024