2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-3676admin/gallery_admin.php in planetGallery before 14.07.2006 allows remote attackers to execute arbitrary PHP code by uplo...
CVE-2006-3781Unspecified vulnerability in Sun Solaris 10 allows context-dependent attackers to cause a denial of service (panic) via ...
CVE-2006-3776PHP remote file inclusion vulnerability in order/index.php in IDevSpot (1) PhpHostBot 1.0 and (2) AutoHost 3.0 allows re...
CVE-2006-3775SQL injection vulnerability in the init function in class_session.php in MyBB (aka MyBulletinBoard) 1.1.5 allows remote ...
CVE-2006-3777PHP remote file inclusion vulnerability in index.php in IDevSpot PhpLinkExchange 1.0 allows remote attackers to execute ...
CVE-2006-3774PHP remote file inclusion vulnerability in performs.php in the perForms component (com_performs) 1.0 and earlier for Joo...
CVE-2006-3773PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M...
CVE-2006-3772PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu...
CVE-2006-3771Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac...
CVE-2006-3770Multiple SQL injection vulnerabilities in index.php in phpFaber TopSites 2.0.9 and earlier allow remote attackers to exe...
CVE-2006-3769Multiple cross-site scripting (XSS) vulnerabilities in Top XL 1.1 and earlier allow remote attackers to inject arbitrary...
CVE-2006-3778IBM Lotus Notes 6.0, 6.5, and 7.0 does not properly handle replies to e-mail messages with alternate name users when the...
CVE-2006-3779Citrix MetaFrame up to XP 1.0 Feature 1, except when running on Windows Server 2003, installs a registry key with an ins...
CVE-2006-3800Cross-site scripting (XSS) vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to inject arb...
CVE-2006-3799DeluxeBB 1.07 and earlier allows remote attackers to bypass SQL injection protection mechanisms via the login variable a...
CVE-2006-3798DeluxeBB 1.07 and earlier allows remote attackers to overwrite the (1) _GET, (2) _POST, (3) _ENV, and (4) _SERVER variab...
CVE-2006-3796DeluxeBB 1.07 and earlier does not properly handle a username composed of a single space character, which allows remote ...
CVE-2006-3795Multiple cross-site scripting (XSS) vulnerabilities in DeluxeBB before 1.08 allow remote attackers to inject arbitrary w...
CVE-2006-3794SQL injection vulnerability in Amazing Flash AFCommerce Shopping Cart allows remote attackers to execute arbitrary SQL c...
CVE-2006-3793PHP remote file inclusion vulnerability in constants.php in SiteDepth CMS 3.01 and earlier allows remote attackers to ex...
CVE-2006-3780Keyifweb Keyif Portal 2.0 stores sensitive information under the web root with insufficient access control, which allows...
CVE-2006-3797SQL injection vulnerability in DeluxeBB 1.07 and earlier allows remote attackers to bypass authentication, spoof users, ...
CVE-2006-3792SQL injection vulnerability in ServerClientUfo::recv_packet in server_protocol.cpp in UFO2000 svn 1057 allows remote att...
CVE-2006-3791The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of ...
CVE-2006-3790The decode_stringmap function in server_transport.cpp for UFO2000 svn 1057 allows remote attackers to cause a denial of ...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now