2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-2523PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a...
CVE-2006-2522Dayfox Blog 2.0 and earlier stores user credentials in edit/slog_users.txt under the web document root with insufficient...
CVE-2006-2521PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to exec...
CVE-2006-2520Directory traversal vulnerability in BitZipper 4.1.2 SR-1 and earlier allows remote attackers to create files in arbitra...
CVE-2006-2514Coppermine galleries before 1.4.6, when running on Apache with mod_mime installed, allows remote attackers to upload arb...
CVE-2006-2518Cross-site scripting (XSS) vulnerability in phpwcms 1.2.5-DEV allows remote attackers to inject arbitrary web script or ...
CVE-2006-2517SQL injection vulnerability in MyWeb Portal Office, Standard Edition, Public Edition, Medical Edition, Citizen Edition, ...
CVE-2006-2516mainfile.php in XOOPS 2.0.13.2 and earlier, when register_globals is enabled, allows remote attackers to overwrite varia...
CVE-2006-2515Cross-site scripting (XSS) vulnerability in index.php in Hiox Guestbook 3.1 allows remote attackers to inject arbitrary ...
CVE-2006-2512SQL injection vulnerability in Hitachi EUR Professional Edition, EUR Viewer, EUR Print Service, and EUR Print Service fo...
CVE-2006-2513Unspecified vulnerability in the installation process in Sun Java System Directory Server 5.2 causes wrong user data to ...
CVE-2006-2507Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing 0.2.0 through 0.7.0, as used with phpBB, allow r...
CVE-2006-2505Oracle Database Server 10g Release 2 allows local users to execute arbitrary SQL queries via a reference to a malicious ...
CVE-2006-2509SQL injection vulnerability in login.php in YourFreeWorld.com Short Url & Url Tracker Script allows remote attackers to ...
CVE-2006-2508SQL injection vulnerability in tr1.php in YourFreeWorld.com Stylish Text Ads Script allows remote attackers to execute a...
CVE-2006-2503SQL injection vulnerability in misc.php in DeluxeBB 1.06 allows remote attackers to execute arbitrary SQL commands via t...
CVE-2006-2506Multiple cross-site scripting (XSS) vulnerabilities in search.php in Sphider allow remote attackers to inject arbitrary ...
CVE-2006-2511The ActiveX version of FrontRange iHEAT allows remote authenticated users to run arbitrary programs or access arbitrary ...
CVE-2006-2510Cross-site scripting (XSS) vulnerability in the URL submission form in YourFreeWorld.com Short Url & Url Tracker Script ...
CVE-2006-2504Multiple SQL injection vulnerabilities in mono AZBOARD 1.0 and earlier allow remote attackers to execute arbitrary SQL c...
CVE-2006-2185PORTAL.NLM in Novell Netware 6.5 SP5 writes the username and password in cleartext to the abend.log log file when the gr...
CVE-2006-2502Stack-based buffer overflow in pop3d in Cyrus IMAPD (cyrus-imapd) 2.3.2, when the popsubfolders option is enabled, allow...
CVE-2006-1858SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) and possibly execute ...
CVE-2006-1857Buffer overflow in SCTP in Linux kernel before 2.6.16.17 allows remote attackers to cause a denial of service (crash) an...
CVE-2006-2498Invision Power Board (IPB) before 2.1.6 allows remote attackers to execute arbitrary PHP script via attack vectors invol...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now