2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

CVE IDSeverityCVSSDescription
CVE-2006-1026JFacets before 0.2 allows remote attackers to gain privileges as any account via a GET request with a modified account p...
CVE-2006-1027feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to obtain sensitive infor...
CVE-2006-1021Cross-site scripting (XSS) vulnerability in sol_menu.php in PeHePe Uyelik Sistemi (aka PeHePe MemberShip Management Syst...
CVE-2006-1028feedcreator.class.php (aka the syndication component) in Joomla! 1.0.7 allows remote attackers to cause a denial of serv...
CVE-2006-1029The cross-site scripting (XSS) countermeasures in class.inputfilter.php in Joomla! 1.0.7 allow remote attackers to cause...
CVE-2006-1030Unspecified vulnerability in mod_templatechooser in Joomla! 1.0.7 allows remote attackers to obtain sensitive informatio...
CVE-2006-1017The c-client library 2000, 2001, or 2004 for PHP before 4.4.4 and 5.x before 5.1.5 do not check the (1) safe_mode or (2)...
CVE-2006-1023Directory traversal vulnerability in HP System Management Homepage (SMH) 2.0.0 through 2.1.4 on Windows allows remote at...
CVE-2006-1025Cross-site scripting (XSS) vulnerability in manage.asp in Addsoft StoreBot 2002 Standard allows remote attackers to inje...
CVE-2006-1020SQL injection vulnerability in forumlib.php in Johnny_Vegas Vegas Forum 1.0 allows remote attackers to execute arbitrary...
CVE-2006-1019Cross-site scripting (XSS) vulnerability in fce.php in UKiBoard 3.0.1 allows remote attackers to inject arbitrary web sc...
CVE-2006-1018SQL injection vulnerability in poems.php in DCI-Designs Dawaween 1.03 allows remote attackers to execute arbitrary SQL c...
CVE-2006-1014Argument injection vulnerability in certain PHP 4.x and 5.x applications, when used with sendmail and when accepting rem...
CVE-2006-1013PHP remote file include vulnerability in index.php in SMartBlog (aka SMBlog) 1.2 allows remote attackers to include and ...
CVE-2006-1015Argument injection vulnerability in certain PHP 3.x, 4.x, and 5.x applications, when used with sendmail and when accepti...
CVE-2006-1016Buffer overflow in the IsComponentInstalled method in Internet Explorer 6.0, when used on Windows 2000 before SP4 or Win...
CVE-2006-0458The DCC ACCEPT command handler in irssi before 0.8.9+0.8.10rc5-0ubuntu4.1 in Ubuntu Linux, and possibly other distributi...
CVE-2006-0815NetworkActiv Web Server 3.5.15 allows remote attackers to read script source code via a crafted URL with a "/" (forward ...
CVE-2006-1012SQL injection vulnerability in WordPress 1.5.2, and possibly other versions before 2.0, allows remote attackers to execu...
CVE-2006-0949RaidenHTTPD 1.1.47 allows remote attackers to obtain source code of script files, including PHP, via crafted requests in...
CVE-2006-0814response.c in Lighttpd 1.4.10 and possibly previous versions, when run on Windows, allows remote attackers to read arbit...
CVE-2006-1011LetterMerger 1.2 stores user information in Access database files with insecure permissions, which allows local users to...
CVE-2006-1010Buffer overflow in socket/request.c in CrossFire before 1.9.0, when oldsocketmode is enabled, allows remote attackers to...
CVE-2006-1001SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote ...
CVE-2006-1000Multiple SQL injection vulnerabilities in Pentacle In-Out Board 3.0 and earlier allow remote attackers to execute arbitr...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now