2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-1077Multiple cross-site scripting (XSS) vulnerabilities in the commentary in Evo-Dev evoBlog allow remote attackers to injec...
CVE-2006-1079htpasswd, as used in Acme thttpd 2.25b and possibly other products such as Apache, might allow local users to gain privi...
CVE-2006-1085admin.php in PHP-Stats 0.1.9.1 and earlier allows remote attackers to bypass authentication, gain administrator privileg...
CVE-2006-1080Cross-site scripting (XSS) vulnerability in login.php in Game-Panel 2.6.1 and earlier allows remote attackers to inject ...
CVE-2006-1081SQL injection vulnerability in forgotten_password.php in Jonathan Beckett PluggedOut Nexus 0.1 allows remote attackers t...
CVE-2006-1088PHP-Stats 0.1.9.1 and earlier allows remote attackers to obtain potentially sensitive information via a direct request t...
CVE-2006-1086Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2006-1083. Reason: This candidate is a duplicate of...
CVE-2006-1087Direct static code injection vulnerability in the modify_config action in admin.php for PHP-Stats 0.1.9.1 and earlier al...
CVE-2006-1074Jason Boettcher Liero Xtreme 0.62b and earlier allow remote attackers to cause a denial of service (application crash or...
CVE-2006-1075Format string vulnerability in the visualization function in Jason Boettcher Liero Xtreme 0.62b and earlier allows remot...
CVE-2006-1076SQL injection vulnerability in index.php, possibly during a showtopic operation, in Invision Power Board (IPB) 2.1.5 all...
CVE-2006-1070Cross-site scripting (XSS) vulnerability in dv_gbook.php in DVguestbook 1.0 allows remote attackers to inject arbitrary ...
CVE-2006-1072Cross-site scripting (XSS) vulnerability in Daverave Simplog 1.0.2 and earlier allows remote attackers to inject arbitra...
CVE-2006-1073Directory traversal vulnerability in index.php in Daverave Simplog 1.0.2 and earlier allows remote attackers to include ...
CVE-2006-1071Cross-site scripting (XSS) vulnerability in index.php in DVguestbook 1.2.2 allows remote attackers to inject arbitrary w...
CVE-2006-1069Unspecified vulnerability in the session handling for Geeklog 1.4.x before 1.4.0sr2, 1.3.11 before 1.3.11sr5, 1.3.9 befo...
CVE-2006-1065SQL injection vulnerability in search.php in MyBulletinBoard (MyBB) 1.04 allows remote attackers to execute arbitrary SQ...
CVE-2006-1068Netgear 614 and 624 routers, possibly running VXWorks, allow remote attackers to cause a denial of service by sending a ...
CVE-2006-1067Linksys WRT54G routers version 5 (running VXWorks) allow remote attackers to cause a denial of service by sending a malf...
CVE-2006-1064Multiple cross-site scripting (XSS) vulnerabilities in Lurker 2.0 and earlier allow remote attackers to inject arbitrary...
CVE-2006-1063Unspecified vulnerability in Lurker 2.0 and earlier allows remote attackers to create or overwrite files in any writable...
CVE-2006-1062Unspecified vulnerability in lurker.cgi for Lurker 2.0 and earlier allows attackers to read arbitrary files via unknown ...
CVE-2006-1051SQL injection vulnerability in Akarru Social BookMarking Engine before 0.4.3.4 allows remote attackers to execute arbitr...
CVE-2006-1050Kwik-Pay Payroll 4.2.20, and possibly other versions, stores the KwikPay.mdb database file with insecure permissions, wh...
CVE-2006-1034Multiple cross-site scripting (XSS) vulnerabilities in Woltlab Burning Board (wBB) allow remote attackers to inject arbi...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now