2006 CVE Vulnerabilities

7,145 CVEs published in 2006.

Filter:UNKNOWNClear
CVE IDSeverityCVSSDescription
CVE-2006-4954——The updateuser servlet in Neon WebMail for Java before 5.08 does not validate the in_id parameter, which allows remote a...
CVE-2006-4963——Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitr...
CVE-2006-4956——Cross-site scripting (XSS) vulnerability in the updateuser servlet in Neon WebMail for Java before 5.08 allows remote at...
CVE-2006-4957——SQL injection vulnerability in the GetMember function in functions.php in MyReview 1.9.4 allows remote attackers to exec...
CVE-2006-4958——Multiple cross-site scripting (XSS) vulnerabilities in Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.20.983 ...
CVE-2006-4959——Sun Secure Global Desktop (SSGD, aka Tarantella) before 4.3 allows remote attackers to obtain sensitive information, inc...
CVE-2006-4960——Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec...
CVE-2006-4961——SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dr...
CVE-2006-4964——Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitr...
CVE-2006-4947——Cross-site scripting (XSS) vulnerability in the Drupal 4.7 Search Keywords module before 1.15 2006/09/15 allows remote a...
CVE-2006-4949——Cross-site scripting (XSS) vulnerability in the Drupal 4.6 Site Profile Directory (profile_pages.module) before 1.1.2.1 ...
CVE-2006-4946——PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0....
CVE-2006-4945——Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al...
CVE-2006-4948——Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to...
CVE-2006-4944——PHP remote file inclusion vulnerability in includes/pear/Net/DNS/RR.php in ProgSys 0.151 and earlier allows remote attac...
CVE-2006-4943——course/jumpto.php in Moodle before 1.6.2 does not validate the session key (sesskey) before providing content from arbit...
CVE-2006-4935——The Database module in Moodle before 1.6.2 does not properly handle uploaded files, which has unspecified impact and rem...
CVE-2006-4936——Moodle before 1.6.2 does not properly validate the module instance id when creating a course module object, which has un...
CVE-2006-4937——lib/setup.php in Moodle before 1.6.2 sets the error reporting level to 7 to display E_WARNING messages to users even if ...
CVE-2006-4938——help.php in Moodle before 1.6.2 does not check the existence of certain help files before including them, which might al...
CVE-2006-4939——backup/backup_scheduled.php in Moodle before 1.6.2 generates trace data with the full backup pathname even when debuggin...
CVE-2006-4940——login/forgot_password.php in Moodle before 1.6.2 allows remote attackers to obtain sensitive information (e-mail address...
CVE-2006-4941——Multiple cross-site scripting (XSS) vulnerabilities in Moodle before 1.6.2 might allow remote attackers to inject arbitr...
CVE-2006-4942——Moodle before 1.6.2, when the configuration lacks (1) algebra or (2) tex filters, allows remote authenticated users to w...
CVE-2006-4899——The ePPIServlet script in Computer Associates (CA) eTrust Security Command Center 1.0 and r8 up to SP1 CR2, when running...

Check if your code is affected by 2006 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now