Skip to main content

Year archive

CVEs published in 2006

Archive summary

6,608 CVEs published in 2006 — 433 Critical, 2,341 High, 3,325 Medium, 509 Low, 0 Unrated.

CVE-2006-0370

Published Jan 22, 2006

Noah Medling RCBlog 1.03 stores the data and config directories under the web root with insufficient access control, which allows remote attackers to view account names and MD5 pa…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0371

Published Jan 22, 2006

Directory traversal vulnerability in index.php in Noah Medling RCBlog 1.03 allows remote attackers to read arbitrary .txt files, possibly including one that stores the administrat…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0372

Published Jan 22, 2006

Multiple SQL injection vulnerabilities in config.php in Insane Visions BlogPHP, possibly 1.0, allow remote attackers to execute arbitrary SQL commands via the (1) blogphp_username…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0373

Published Jan 22, 2006

Cross-site scripting (XSS) vulnerability in register.aspx in Douran FollowWeb allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors. NOTE: the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0374

Published Jan 22, 2006

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 has multiple undocumented ports available, which (1) might allow remote attackers to obtai…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0375

Published Jan 22, 2006

Advantage Century Telecommunication (ACT) P202S IP Phone 1.01.21 running firmware 1.1.21 on VxWorks uses a hardcoded Network Time Protocol (NTP) server in Taiwan, which could allo…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0353

Published Jan 22, 2006

unix_random.c in lshd for lsh 2.0.1 leaks file descriptors related to the randomness generator, which allows local users to cause a denial of service by truncating the seed file,…

CVSS 3.6 · Low
Vendor/product tagsBeta · best-effort

CVE-2006-0345

Published Jan 21, 2006

Multiple SQL injection vulnerabilities in SaralBlog 1.0 allow remote attackers to execute arbitrary SQL commands via the search parameter to search.php. NOTE: the id/viewprofile.…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0346

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in SaralBlog 1.0 allows remote attackers to inject arbitrary web script or HTML via a website field in a new comment to view.php, which is…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0347

Published Jan 21, 2006

Directory traversal vulnerability in ELOG before 2.6.1 allows remote attackers to access arbitrary files outside of the elog directory via "../" (dot dot) sequences in the URL.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0348

Published Jan 21, 2006

Format string vulnerability in the write_logfile function in ELOG before 2.6.1 allows remote attackers to cause a denial of service (server crash) via unknown attack vectors. NOT…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0349

Published Jan 21, 2006

SQL injection vulnerability in eggblog 2.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to blog.php.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0350

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in eggblog 2.0 allow remote attackers to inject arbitrary web script or HTML via the message field to topic.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0351

Published Jan 21, 2006

Unspecified "critical denial-of-service vulnerability" in MyDNS before 1.1.0 has unknown impact and attack vectors.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0352

Published Jan 21, 2006

The default configuration of Fluffington FLog 1.01 installs users.0.dat under the web document root with insufficient access control, which might allow remote attackers to obtain…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0327

Published Jan 21, 2006

TYPO3 3.7.1 allows remote attackers to obtain sensitive information via a direct request to (1) thumbs.php, (2) showpic.php, or (3) tables.php, which causes them to incorrectly de…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0328

Published Jan 21, 2006

Format string vulnerability in Tftpd32 2.81 allows remote attackers to cause a denial of service via format string specifiers in a filename in a (1) GET or (2) SEND request.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0329

Published Jan 21, 2006

SQL injection vulnerability in HITSENSER Data Mart Server BS, BS-S, BS-M, BS-L, and EX allows remote attackers to execute arbitrary SQL commands via unknown attack vectors.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2006-0330

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in Gallery before 1.5.2 allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors, possibly involving the…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0331

Published Jan 21, 2006

Buffer overflow in Change passwd 3.1 (chpasswd) SquirrelMail plugin allows local users to execute arbitrary code via long command line arguments.

CVSS 4.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0332

Published Jan 21, 2006

Pantomime in Ecartis 1.0.0 snapshot 20050909 stores e-mail attachments in a publicly accessible directory, which may allow remote attackers to upload arbitrary files.

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0333

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in ar-blog 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) month or (2) year parameter to index.php.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0334

Published Jan 21, 2006

Cross-site scripting (XSS) vulnerability in search.php in My Amazon Store Manager 1.0 allows remote attackers to inject arbitrary web script or HTML via the Keywords parameter. N…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2006-0335

Published Jan 21, 2006

Multiple unspecified vulnerabilities in Kerio WinRoute Firewall before 6.1.4 Patch 1 allow remote attackers to cause a denial of service via multiple unspecified vectors involving…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort
Showing 6,326-6,350 of 6,608 CVEsPage 254 of 265