LiveActive security incident?Get immediate response
CVE archive

2006 CVE Archive

Browse CVE records published in 2006 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6995 matching CVEs · Page 13 of 140.

Unknown · CVSS Not scored

CVE-2006-6833: com_categories in Joomla!

com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6832: Cross-site scripting (XSS) vulnerability in Joomla!

Cross-site scripting (XSS) vulnerability in Joomla! before 1.0.12 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, possibly related to poll.php or the module title.

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6824: Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and ea...

Multiple cross-site scripting (XSS) vulnerabilities in Jim Hu and Chad Little PHP iCalendar 2.23 rc1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) getdate parameter in (a) day.php, (b) month.php, (c) year.php, (d) week.php, (e) search.php, (f) rss/index.php, (g) print.php, and (h) preferences.php; the (2) cpath parameter in (i) day.php, (j) month.php, (k) year.php, (l) week.php, and (m) search.php; the (3) query parameter in search.php; and possibly the cpath, (4) unset, and (5) set parameters in a setcookie action in preferences.php; different vectors than CVE-2006-3319. NOTE: it was later reported that vectors b, c, and d also affect 2.24.

Published Dec 29, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6834: Multiple unspecified vulnerabilities in Joomla!

Multiple unspecified vulnerabilities in Joomla! before 1.0.12 have unknown impact and attack vectors related to (1) "unneeded legacy functions" and (2) "Several low level security fixes."

Published Jan 1, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6816: Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execu...

Multiple SQL injection vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel; (4) the sent parameter to (a) login.asp, (b) content.asp, and (c) members.asp in the Remote-WebSite; and (5) the sent parameter to applications/SecureLoginManager/inc_secureloginmanager.asp in the Live Demo.

Published Dec 29, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6825: Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access...

Calendar MX BASIC 1.0.2 and earlier store sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for calendar.mdb. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 29, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6852: Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execu...

Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml. NOTE: some of these details are obtained from third party information.

Published Jan 4, 2007 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6799: SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote...

SQL injection vulnerability in Cacti 0.8.6i and earlier, when register_argc_argv is enabled, allows remote attackers to execute arbitrary SQL commands via the (1) second or (2) third arguments to cmd.php. NOTE: this issue can be leveraged to execute arbitrary commands since the SQL query results are later used in the polling_items array and popen function.

Published Dec 28, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6815: Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authe...

Multiple cross-site scripting (XSS) vulnerabilities in DMXReady Secure Login Manager 1.0 allow remote authenticated administrators to inject arbitrary web script or HTML via unspecified parameters to (1) set_preferences.asp, (2) send_password_preferences.asp, and (3) SecureLoginManager/list.asp in the Local-Admin Panel.

Published Dec 29, 2006 · Updated Aug 7, 2024