LiveActive security incident?Get immediate response
CVE archive

January 2006

Browse CVE records published in January 2006, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 561 matching CVEs · Page 3 of 12.

Unknown · CVSS Not scored

CVE-2006-6869: Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier...

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

Published Jan 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6867: Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla)...

Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different vectors and a different affected version than CVE-2006-6809.

Published Jan 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6829: Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control...

Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6828: Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arb...

Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. The default.asp/grup vector is already covered by CVE-2006-6794.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6833: com_categories in Joomla!

com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6832: Cross-site scripting (XSS) vulnerability in Joomla!

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6834: Multiple unspecified vulnerabilities in Joomla!

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

Published Jan 1, 2007 · Updated Aug 7, 2024