2006 CVE Vulnerabilities
7,145 CVEs published in 2006.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2006-0695 | — | — | 2.7% | Feb 15, 2006 | Ansilove before 1.03 does not filter uploaded file extensions, which allows remote attackers to execute arbitrary code b... |
| CVE-2006-0696 | — | — | 1.2% | Feb 15, 2006 | SQL injection vulnerability in Zen Cart before 1.2.7 allows remote attackers to execute arbitrary SQL commands via unspe... |
| CVE-2006-0697 | — | — | 5.2% | Feb 15, 2006 | Zen Cart before 1.2.7 does not protect the admin/includes directory, which allows remote attackers to cause unknown impa... |
| CVE-2006-0698 | — | — | 1.9% | Feb 15, 2006 | Unspecified vulnerabilities in Zen Cart before 1.2.7 allow remote attackers to cause unknown impact via unspecified vect... |
| CVE-2006-0699 | — | — | 1.7% | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in search.php in QWikiWiki 1.5, and possibly 1.5.1 and other versions, allows r... |
| CVE-2006-0700 | — | — | 6.5% | Feb 15, 2006 | imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which return... |
| CVE-2006-0701 | — | — | 7.7% | Feb 15, 2006 | readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters. |
| CVE-2006-0702 | — | — | 7.1% | Feb 15, 2006 | admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (d... |
| CVE-2006-0703 | — | — | 4.4% | Feb 15, 2006 | Unspecified vulnerability in index.php in imageVue 16.1 has unknown impact, probably a cross-site scripting (XSS) vulner... |
| CVE-2006-0704 | — | — | 1.2% | Feb 15, 2006 | iE Integrator 4.4.220114, when configured without a "bespoke error page" in acm.ini, allows remote attackers to obtain s... |
| CVE-2006-0705 | — | — | 10.2% | Feb 15, 2006 | Format string vulnerability in a logging function as used by various SFTP servers, including (1) AttachmateWRQ Reflectio... |
| CVE-2006-0706 | — | — | 2.3% | Feb 15, 2006 | Cross-site scripting vulnerability in eintrag.php in Gästebuch (Gastebuch) before 1.3.3 allows remote attackers to injec... |
| CVE-2006-0707 | — | — | 1.4% | Feb 15, 2006 | PyBlosxom before 1.3.2, when running on certain webservers, allows remote attackers to read arbitrary files via an HTTP ... |
| CVE-2006-0708 | — | — | 7.1% | Feb 15, 2006 | Multiple buffer overflows in NullSoft Winamp 5.13 and earlier allow remote attackers to execute arbitrary code via (1) a... |
| CVE-2006-0709 | — | — | 6.3% | Feb 15, 2006 | Buffer overflow in Metamail 2.7-50 allows remote attackers to cause a denial of service (application crash) or possibly ... |
| CVE-2006-0710 | — | — | 4.4% | Feb 15, 2006 | Double free vulnerability in isode.eddy in Isode M-Vault Server 11.3 allows remote attackers to execute arbitrary code v... |
| CVE-2006-0711 | — | — | 1.5% | Feb 15, 2006 | The (1) addfolder and (2) deletefolder functions in neomail-prefs.pl in NeoMail 1.28 do not validate the Session ID, whi... |
| CVE-2006-0712 | — | — | 1.6% | Feb 15, 2006 | mail_html template in Squishdot 1.5.0 and earlier does not properly validate the (1) email and (2) title variables, whic... |
| CVE-2006-0713 | — | — | 3.0% | Feb 15, 2006 | Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ... |
| CVE-2006-0714 | — | — | 7.6% | Feb 15, 2006 | Directory traversal vulnerability in the installation file (sql/install-0.9.7.php) in Flyspray 0.9.7 allows remote attac... |
| CVE-2006-0715 | — | — | 1.7% | Feb 15, 2006 | Cross-site scripting (XSS) vulnerability in sNews 1.3 allows remote attackers to inject arbitrary web script or HTML via... |
| CVE-2006-0716 | — | — | 1.3% | Feb 15, 2006 | SQL injection vulnerability in index.php in sNews 1.3 allows remote attackers to execute arbitrary SQL commands via the ... |
| CVE-2006-0717 | — | — | 9.4% | Feb 15, 2006 | IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request,... |
| CVE-2006-0687 | — | — | 2.7% | Feb 15, 2006 | process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows r... |
| CVE-2006-0680 | — | — | 1.4% | Feb 15, 2006 | Unspecified vulnerability in WebGUI before 6.8.6-gamma allows remote attackers to create an account, when anonymous regi... |
Check if your code is affected by 2006 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now