Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-6630

Published Dec 18, 2006

PHP remote file inclusion vulnerability in ListRecords.php in osprey 1.0 allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6631

Published Dec 18, 2006

PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the lib_dir param…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6632

Published Dec 18, 2006

PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the topdir parameter.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6633

Published Dec 18, 2006

PHP remote file inclusion vulnerability in include/yapbb_session.php in YapBB 1.2 Beta2 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6634

Published Dec 18, 2006

Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for Mambo allow remote attackers to execute arbitrary PHP code v…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6635

Published Dec 18, 2006

PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute arbitrary PHP code via a URL in the jcms_root_path parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6606

Published Dec 18, 2006

Multiple SQL injection vulnerabilities in Clarens jclarens before 0.6.2 allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6607

Published Dec 18, 2006

The Java Key Store (JKS) for WebSphere Application Server (WAS) for IBM Tivoli Identity Manager (ITIM) 4.6 places the JKS password in a -Djavax.net.ssl.trustStorePassword command…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-6609

Published Dec 18, 2006

Nexuiz before 2.2.1 allows remote attackers to cause a denial of service (resource exhaustion or crash) via unspecified vectors related to "fake players." NOTE: some of these deta…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6610

Published Dec 18, 2006

clientcommands in Nexuiz before 2.2.1 has unknown impact and remote attack vectors related to "remote console command injection."

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6611

Published Dec 18, 2006

PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6612

Published Dec 18, 2006

PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PHP code via a URL in the basepath_start parameter.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6613

Published Dec 18, 2006

Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6615

Published Dec 18, 2006

PHP remote file inclusion vulnerability in includes/act_constants.php in the Activity Games (mx_act) 0.92 module for mxBB allows remote attackers to execute arbitrary PHP code via…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6616

Published Dec 18, 2006

index.php in w00t Gallery 1.4.0 allows remote authenticated users with privileges for one installation to gain access to other installations on the same web server, aka "multi-gal…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-5872

Published Dec 18, 2006

login.pl in SQL-Ledger before 2.6.21 and LedgerSMB before 1.1.5 allows remote attackers to execute arbitrary Perl code via the "-e" flag in the script parameter, which is used as…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-6596

Published Dec 15, 2006

HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via a session (HAW) file, which can be automatically opened using Internet Explore…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6597

Published Dec 15, 2006

Argument injection vulnerability in HyperAccess 8.4 allows user-assisted remote attackers to execute arbitrary vbscript and commands via the /r option in a telnet:// URI, which is…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6599

Published Dec 15, 2006

maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters (";" semicolon) in the announce parameter.

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6600

Published Dec 15, 2006

Cross-site scripting (XSS) vulnerability in dir.php in TorrentFlux 2.2, when allows remote attackers to inject arbitrary web script or HTML via double URL-encoded strings in the d…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-6601

Published Dec 15, 2006

Windows Media Player 10.00.00.4036 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause a denial of service via a .MID (MIDI) file with a malformed header ch…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 351-375 of 6,608 CVEsPage 15 of 265