2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2006-7020——CRLF injection vulnerability in (1) include/inc_act/act_formmailer.php and possibly (2) sample_ext_php/mail_file_form.ph...
CVE-2006-7021——PHP remote file inclusion vulnerability in manager/tools/link/dbinstall.php in Plume CMS 1.1.3 allows remote attackers t...
CVE-2006-7022——The Tools module in fx-APP 0.0.8.1 allows remote attackers to misrepresent the contents of a web page via an arbitrary U...
CVE-2006-7023——Multiple cross-site scripting (XSS) vulnerabilities in fx-APP 0.0.8.1 allow remote attackers to inject arbitrary HTML or...
CVE-2006-5860——Cross-site scripting (XSS) vulnerability in the administrator console for Adobe JRun 4.0, as used in ColdFusion, allows ...
CVE-2006-5859——Cross-site scripting (XSS) vulnerability in Adobe ColdFusion MX 7 7.0 and 7.0.1, when Global Script Protection is not en...
CVE-2006-4697——Microsoft Internet Explorer 5.01, 6, and 7 uses certain COM objects from Imjpcksid.dll as ActiveX controls, which allows...
CVE-2006-3448——Buffer overflow in the Step-by-Step Interactive Training in Microsoft Windows 2000 SP4, XP SP2 and Professional, and Ser...
CVE-2006-5270——Integer overflow in the Microsoft Malware Protection Engine (mpengine.dll), as used by Windows Live OneCare, Antigen, De...
CVE-2006-1311——The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Offic...
CVE-2006-7003——PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary ...
CVE-2006-7004——Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary...
CVE-2006-7006——PHP remote file inclusion vulnerability in upload/admin/team.php in Robin de Graff Somery 0.4.4 allows remote attackers ...
CVE-2006-7007——Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a l...
CVE-2006-7008——Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg fr...
CVE-2006-7009——Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attac...
CVE-2006-7010——The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variabl...
CVE-2006-7005——SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the...
CVE-2006-7002——Cross-site scripting (XSS) vulnerability in add_comment.php in Wheatblog (wB) 1.1 allows remote attackers to inject arbi...
CVE-2006-7001——Directory traversal vulnerability in avatar.php in PhpMyChat Plus 1.9 and earlier allows remote attackers to read arbitr...
CVE-2006-6998——install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a...
CVE-2006-6999——attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file n...
CVE-2006-7000——Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (...
CVE-2006-6993——Multiple SQL injection vulnerabilities in pages/addcomment2.php in Neuron Blog 1.1 allow remote attackers to inject arbi...
CVE-2006-6996——Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now