2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-3408Unspecified vulnerability in the directory server (dirserver) in Tor before 0.1.1.20 allows remote attackers to cause an...
CVE-2006-3411TLS handshakes in Tor before 0.1.1.20 generate public-private keys based on TLS context rather than the connection, whic...
CVE-2006-3418Tor before 0.1.1.20 does not validate that a server descriptor's fingerprint line matches its identity key, which allows...
CVE-2006-3419Tor before 0.1.1.20 uses OpenSSL pseudo-random bytes (RAND_pseudo_bytes) instead of cryptographically strong RAND_bytes,...
CVE-2006-3420Cross-site request forgery (CSRF) vulnerability in editpost.php in MyBulletinBoard (MyBB) before 1.1.5 allows remote att...
CVE-2006-3421PHP remote file inclusion vulnerability in SmartSiteCMS 1.0 and earlier, when register_globals is enabled, allows remote...
CVE-2006-3380Algorithmic complexity vulnerability in FreeStyle Wiki before 3.6.2 allows remote attackers to cause a denial of service...
CVE-2006-3382Cross-site scripting (XSS) vulnerability in search.php in mAds 1.0 allows remote attackers to inject arbitrary web scrip...
CVE-2006-3383Cross-site scripting (XSS) vulnerability in index.php in mAds 1.0 allows remote attackers to inject arbitrary web script...
CVE-2006-3384SQL injection vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to execute arbitrary SQL ...
CVE-2006-3385Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject ar...
CVE-2006-3386index.php in Vincent Leclercq News 5.2 allows remote attackers to obtain sensitive information, such as the installation...
CVE-2006-3387Directory traversal vulnerability in sources/post.php in Fusion News 1.0, when register_globals is enabled, allows remot...
CVE-2006-3388Cross-site scripting (XSS) vulnerability in phpMyAdmin before 2.8.2 allows remote attackers to inject arbitrary web scri...
CVE-2006-3389index.php in WordPress 2.0.3 allows remote attackers to obtain sensitive information, such as SQL table prefixes, via an...
CVE-2006-3390WordPress 2.0.3 allows remote attackers to obtain the installation path via a direct request to various files, such as t...
CVE-2006-3391The Execute function in iMBCContents ActiveX Control before 2.0.0.59 allows remote attackers to execute arbitrary files ...
CVE-2006-3392Webmin before 1.290 and Usermin before 1.220 calls the simplify_path function before decoding HTML, which allows remote ...
CVE-2006-3393Papyrus NASCAR Racing 4 4.1.3.1.6 and earlier, 2002 Season 1.1.0.2 and earlier, and 2003 Season 1.2.0.1 and earlier allo...
CVE-2006-3394SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary S...
CVE-2006-3395PHP remote file inclusion vulnerability in top.php in SiteBuilder-FX 3.5 allows remote attackers to execute arbitrary PH...
CVE-2006-3396PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows r...
CVE-2006-3397Multiple cross-site scripting (XSS) vulnerabilities in Taskjitsu before 2.0.1 allow remote attackers to inject arbitrary...
CVE-2006-3398The "change password forms" in Taskjitsu before 2.0.1 includes password hashes in hidden form fields, which allows remot...
CVE-2006-3399Cross-site scripting (XSS) vulnerability in wiki.php in MoniWiki before 1.1.2-20060702 allows remote attackers to inject...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now