LiveActive security incident?Get immediate response
CVE archive

2006 CVE Archive

Browse CVE records published in 2006 CVE Archive, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 6995 matching CVEs · Page 17 of 140.

Unknown · CVSS Not scored

CVE-2006-6661: Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overw...

Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrary program variables and execute arbitrary PHP code via multiple vectors that use the extract function, as demonstrated by the (1) f, (2) newmessage, (3) newusername, (4) adminuser, and (5) permission parameters.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6667: Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbi...

Multiple SQL injection vulnerabilities in VerliAdmin 0.3 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) nick_mod or (2) nick parameter to (a) repass.php or (b) verify.php. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6565: FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard...

FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to the (1) LIST or (2) NLST commands, which results in a NULL pointer dereference, a different set of vectors than CVE-2006-6564. NOTE: CVE analysis suggests that the problem might be due to a malformed PORT command.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6614: The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose...

The save_log_local function in Fully Automatic Installation (FAI) 2.10.1, and possibly 3.1.2, when verbose mode is enabled, stores the root password hash in /var/log/fai/current/fai.log, whose file permissions allow it to be copied to other hosts when fai-savelog is called and allows attackers to obtain the hash.

Published Dec 18, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6641: Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used i...

Unspecified vulnerability in CA CleverPath Portal before maintenance version 4.71.001_179_060830, as used in multiple products including BrightStor Portal r11.1, CleverPath Aion BPM r10 through r10.2, eTrust Security Command Center r1 and r8, and Unicenter, does not properly handle when multiple Portal servers are started at the same time and share the same data store, which might cause a Portal user to inherit the session and credentials of a user who is on another Portal server.

Published Dec 20, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6640: Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inje...

Multiple cross-site scripting (XSS) vulnerabilities in Omniture SiteCatalyst allow remote attackers to inject arbitrary web script or HTML via the (1) ss parameter in (a) search.asp and the (2) company and (3) username fields on (b) the web login page. NOTE: some details were obtained from third party information.

Published Dec 19, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6585: The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, whic...

The Extensions manager in Mozilla Firefox 2.0 does not properly populate the list of local extensions, which allows attackers to construct an extension that hides itself by finding its name in the list and then calling RemoveElement, as demonstrated by the FFsniFF extension. NOTE: it was later reported that 3.0 is also affected.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6589: Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business...

Cross-site scripting (XSS) vulnerability in ecommerce/control/keywordsearch in the Apache Open For Business Project (OFBiz) and Opentaps 0.9.3 allows remote attackers to inject arbitrary web script or HTML via the SEARCH_STRING parameter, a different issue than CVE-2006-6587. NOTE: some of these details are obtained from third party information.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6580: admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allo...

admin/change.php in ProNews 1.5 does not check whether a user is permitted to change news items, which allows remote attackers to add or delete information within an item, and possibly have other impacts. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

Published Dec 15, 2006 · Updated Aug 7, 2024

Unknown · CVSS Not scored

CVE-2006-6613: Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_g...

Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disabled and register_globals is enabled, allows remote attackers to include and execute arbitrary local files or obtain sensitive information via a .. (dot dot) in the pa_lang[include_file] parameter, as demonstrated by injecting PHP sequences into an Apache HTTP Server log file, which is then included by language.php.

Published Dec 18, 2006 · Updated Aug 7, 2024