LiveActive security incident?Get immediate response
CVE archive

2006 CVE Archive

Browse CVE records published in 2006 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6995 matching CVEs · Page 12 of 140.

Unknown · CVSS Not scored

CVE-2006-6871: Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbit...

Multiple cross-site scripting (XSS) vulnerabilities in eNdonesia 8.4 allow remote attackers to inject arbitrary web script or HTML via (1) the mod parameter in a viewlink operation in mod.php, (2) the intypeid parameter in a showinfo operation in the informasi module in mod.php, (3) the "your Friend" field in friend.php, or (4) the "Main Text" field in admin.php.

Published Jan 5, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6869: Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier...

Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the PNSVlang cookie to error.php, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by error.php.

Published Jan 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6867: Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla)...

Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow remote attackers to execute arbitrary PHP code via a URL in the bu_dir parameter to (1) bu/bu_claro.php, (2) bu/bu_cache.php, or (3) bu/bu_parse.php, different vectors and a different affected version than CVE-2006-6809.

Published Jan 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6829: Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control...

Efkan Forum 1.0 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for forum.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6828: Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arb...

Multiple SQL injection vulnerabilities in Efkan Forum 1.0 and earlier allow remote attackers to execute arbitrary SQL commands via (1) the grup parameter in admin.asp, or the id parameter in (2) default.asp or (3) admin.asp. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information. The default.asp/grup vector is already covered by CVE-2006-6794.

Published Jan 1, 2007 · Updated Aug 7, 2024