2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-2615ping.php in Russcom.Ping allows remote attackers to execute arbitrary commands via shell metacharacters in the domain pa...
CVE-2006-2614Sun N1 System Manager 1.1 for Solaris 10 before patch 121161-01 records system passwords in the world-readable scripts (...
CVE-2006-2613Mozilla Suite 1.7.13, Mozilla Firefox 1.5.0.3 and possibly other versions before before 1.8.0, and Netscape 7.2 and 8.1,...
CVE-2006-2612Novell Client for Windows 4.8 and 4.9 does not restrict access to the clipboard contents while a machine is locked, whic...
CVE-2006-2611Cross-site scripting (XSS) vulnerability in includes/Sanitizer.php in the variable handler in MediaWiki 1.6.x before r14...
CVE-2006-2610Cross-site scripting (XSS) vulnerability in view.php in phpRaid 2.9.5 allows remote attackers to inject arbitrary web sc...
CVE-2006-2609artmedic newsletter 4.1.2 and possibly other versions, when register_globals is enabled, allows remote attackers to modi...
CVE-2006-2608artmedic newsletter 4.1 and possibly other versions, when register_globals is enabled, allows remote attackers to modify...
CVE-2006-2607do_command.c in Vixie cron (vixie-cron) 4.1 does not check the return code of a setuid call, which might allow local use...
CVE-2006-2593Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2581. Reason: This candidate is a duplicate of...
CVE-2006-2603Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2591. Reason: This candidate is a duplicate of...
CVE-2006-2601Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2589. Reason: This candidate is a duplicate of...
CVE-2006-2602Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-2590. Reason: This candidate is a duplicate of...
CVE-2006-2605Cross-site scripting (XSS) vulnerability in DSChat 1.0 and earlier allows remote attackers to inject arbitrary web scrip...
CVE-2006-2592Unspecified vulnerability in DSChat 1.0 allows remote attackers to execute arbitrary PHP code via the Nickname field, wh...
CVE-2006-2591Unspecified vulnerability in e107 before 0.7.5 has unknown impact and remote attack vectors related to an "emailing expl...
CVE-2006-2590SQL injection vulnerability in e107 before 0.7.5 allows remote attackers to execute arbitrary SQL commands via unknown a...
CVE-2006-2589SQL injection vulnerability in rss.php in MyBB (aka MyBulletinBoard) 1.1.1 allows remote attackers to execute arbitrary ...
CVE-2006-2588Russcom PHPImages allows remote attackers to upload files of arbitrary types by uploading a file with a .gif extension. ...
CVE-2006-2587Buffer overflow in the WebTool HTTP server component in (1) PunkBuster before 1.229, as used by multiple products includ...
CVE-2006-2586Cross-site scripting (XSS) vulnerability in IpLogger 1.7 and earlier allows remote attackers to inject arbitrary HTML or...
CVE-2006-2585SQL injection vulnerability in Destiney Links Script 2.1.2 allows remote attackers to execute arbitrary SQL commands via...
CVE-2006-2584Multiple cross-site scripting (XSS) vulnerabilities in post.php in SkyeBox 1.2.0 allow remote attackers to inject arbitr...
CVE-2006-2583PHP remote file inclusion vulnerability in nucleus/libs/PLUGINADMIN.php in Nucleus 3.22 and earlier allows remote attack...
CVE-2006-2582The editing form in RWiki 2.1.0pre1 through 2.1.0 allows remote attackers to execute arbitrary Ruby code via unknown att...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now