2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-1311The RichEdit component in Microsoft Windows 2000 SP4, XP SP2, and 2003 SP1; Office 2000 SP3, XP SP3, 2003 SP2, and Offic...
CVE-2006-7003PHP remote file inclusion vulnerability in admin/index.php in Fusion Polls allows remote attackers to execute arbitrary ...
CVE-2006-7004Cross-site scripting (XSS) vulnerability in email_request.php in PSY Auction allows remote attackers to inject arbitrary...
CVE-2006-7006PHP remote file inclusion vulnerability in upload/admin/team.php in Robin de Graff Somery 0.4.4 allows remote attackers ...
CVE-2006-7007Buffer overflow in Tiny FTPd 1.4 and earlier allows remote attackers to cause a denial of service (daemon crash) via a l...
CVE-2006-7008Unspecified vulnerability in Joomla! before 1.0.10 has unknown impact and attack vectors, related to "securing mosmsg fr...
CVE-2006-7009Joomla! before 1.0.10 allows remote attackers to spoof the frontend submission forms, which has unknown impact and attac...
CVE-2006-7010The mosgetparam implementation in Joomla! before 1.0.10, does not set a variable's data type to integer when the variabl...
CVE-2006-7005SQL injection vulnerability in item.php in PSY Auction allows remote attackers to execute arbitrary SQL commands via the...
CVE-2006-7001Directory traversal vulnerability in avatar.php in PhpMyChat Plus 1.9 and earlier allows remote attackers to read arbitr...
CVE-2006-7002Cross-site scripting (XSS) vulnerability in add_comment.php in Wheatblog (wB) 1.1 allows remote attackers to inject arbi...
CVE-2006-6998install/loader_help.php in Headstart Solutions DeskPRO allows remote attackers to obtain configuration information via a...
CVE-2006-6999attachment.php in Headstart Solutions DeskPRO allows remote attackers to read all uploaded files by providing the file n...
CVE-2006-7000Headstart Solutions DeskPRO allows remote attackers to obtain the full path via direct requests to (1) email/mail.php, (...
CVE-2006-6993Multiple SQL injection vulnerabilities in pages/addcomment2.php in Neuron Blog 1.1 allow remote attackers to inject arbi...
CVE-2006-6997Unspecified vulnerability in a cryptographic feature in MailEnable Standard Edition before 1.93, Professional Edition be...
CVE-2006-6996Multiple cross-site scripting (XSS) vulnerabilities in warforge.NEWS 1.0 allow remote attackers to inject arbitrary HTML...
CVE-2006-6994Unrestricted file upload vulnerability in add.asp in OzzyWork Gallery, possibly 2.0 and earlier, allows remote attackers...
CVE-2006-6995mycontacts.php in V3 Chat allows remote authenticated users to gain privileges as other users via a modified membername ...
CVE-2006-6983Cross-domain vulnerability in MYweb4net Browser 3.8.8.0 allows remote attackers to access restricted information from ot...
CVE-2006-6985Cross-domain vulnerability in Maxthon 1.5.6 build 42 allows remote attackers to access restricted information from other...
CVE-2006-6984Cross-domain vulnerability in GreenBrowser 3.4.0622 allows remote attackers to access restricted information from other ...
CVE-2006-6987Cross-domain vulnerability in FineBrowser Freeware 3.2.2 allows remote attackers to access restricted information from o...
CVE-2006-6988Cross-domain vulnerability in Slim Browser 4.07 build 100 allows remote attackers to access restricted information from ...
CVE-2006-6989Cross-domain vulnerability in NetCaptor 4.5.7 Personal Edition allows remote attackers to access restricted information ...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now