CVE-2006-1182
Summary
| CVE | CVE-2006-1182 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2006-03-16 01:02:00 UTC |
| Updated | 2025-04-03 01:03:51 UTC |
| Description | Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command. |
Risk And Classification
Primary CVSS: v2.0 2.6 from [email protected]
AV:L/AC:H/Au:N/C:P/I:P/A:N
EPSS: 0.001810000 probability, percentile 0.398140000 (date 2026-04-17)
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
HighAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
NoneAV:L/AC:H/Au:N/C:P/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Adobe | Document Server | 5.0 | All | All | All |
| Application | Adobe | Document Server | 6.0 | All | All | All |
| Application | Adobe | Graphics Server | 2.0 | All | All | All |
| Application | Adobe | Graphics Server | 2.1 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Adobe Graphics Server / Document Server Remote Command Execution Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Patch |
| SecurityTracker.com Archives - Adobe Document Server Interactive Login Configuration Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | |
| Security Advisory: Adobe Graphics Server and Adobe Document Server configuration security vulnerability - Support Knowledgebase | af854a3a-2127-422b-91ae-364da2661108 | www.adobe.com | Patch |
| SecurityReason | af854a3a-2127-422b-91ae-364da2661108 | securityreason.com | |
| Adobe Document/Graphics Server File URI Resource Access - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| SecurityTracker.com Archives - Adobe Graphics Server Interactive Login Configuration Lets Remote Users Execute Arbitrary Code | af854a3a-2127-422b-91ae-364da2661108 | securitytracker.com | Patch, Vendor Advisory |
| www.osvdb.org/23924 | af854a3a-2127-422b-91ae-364da2661108 | www.osvdb.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.