2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-2771admin/radera/tabort.asp in Hogstorps hogstorp guestbook 2.0 does not verify user credentials, which allows remote attack...
CVE-2006-2774Cross-site scripting (XSS) vulnerability in search.php in QontentOne CMS allows remote attackers to inject arbitrary web...
CVE-2006-2767PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to e...
CVE-2006-2662VMware Server before RC1 does not clear user credentials from memory after a console connection is made, which might all...
CVE-2006-2766Buffer overflow in INETCOMM.DLL, as used in Microsoft Internet Explorer 6.0 through 6.0 SP2, Windows Explorer, Outlook E...
CVE-2006-2764Cross-site scripting (XSS) vulnerability in GuestbookXL 1.3 allows remote attackers to inject arbitrary web script or HT...
CVE-2006-2759jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary script source code via a capital P in the .jsp ext...
CVE-2006-2655The build process for ypserv in FreeBSD 5.3 up to 6.1 accidentally disables access restrictions when using the /var/yp/s...
CVE-2006-2765Cross-site scripting (XSS) vulnerability in news_information.php in Interlink Advantage allows remote attackers to injec...
CVE-2006-2763SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1...
CVE-2006-2762PHP remote file inclusion vulnerability in includes/config.php in WebCalendar 1.0.3 allows remote attackers to execute a...
CVE-2006-2761SQL injection vulnerability in Hitachi HITSENSER3 HITSENSER3/PRP, HITSENSER3/PUP, HITSENSER3/STP, and HITSENSER3/EUP all...
CVE-2006-2760SQL injection vulnerability in modules.php in 4nNukeWare 4nForum 0.91 allows remote attackers to execute arbitrary SQL c...
CVE-2006-2758Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %...
CVE-2006-2757Cross-site scripting (XSS) vulnerability in Chipmunk guestbook allows remote attackers to inject arbitrary web script or...
CVE-2006-2756Eitsop My Web Server 1.0 allows remote attackers to cause a denial of service (application crash) via a long GET request...
CVE-2006-2755Cross-site scripting (XSS) vulnerability in index.php in UBBThreads 5.x and earlier allows remote attackers to inject ar...
CVE-2006-2654Directory traversal vulnerability in smbfs smbfs on FreeBSD 4.10 up to 6.1 allows local users to escape chroot restricti...
CVE-2006-2309The HTTP service in EServ/3 3.25 allows remote attackers to obtain sensitive information via crafted HTTP requests conta...
CVE-2006-2308Directory traversal vulnerability in the IMAP service in EServ/3 3.25 allows remote authenticated users to read other us...
CVE-2006-2754Stack-based buffer overflow in st.c in slurpd for OpenLDAP before 2.3.22 might allow attackers to execute arbitrary code...
CVE-2006-2753SQL injection vulnerability in MySQL 4.1.x before 4.1.20 and 5.0.x before 5.0.22 allows context-dependent attackers to e...
CVE-2006-2749SQL injection vulnerability in search.php in Open Searchable Image Catalogue (OSIC) 0.7.0.1 and earlier allows remote at...
CVE-2006-2748SQL injection vulnerability in the do_mysql_query function in core.php for Open Searchable Image Catalogue (OSIC) before...
CVE-2006-2747Directory traversal vulnerability in index.php in PhpMyDesktop|arcade 1.0 FINAL allows remote attackers to read arbitrar...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now