{"api_version":"1","generated_at":"2026-07-23T11:20:30+00:00","cve":"CVE-2006-1182","urls":{"html":"https://cve.report/CVE-2006-1182","api":"https://cve.report/api/cve/CVE-2006-1182.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1182","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1182"},"summary":{"title":"CVE-2006-1182","description":"Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-16 01:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:L/AC:H/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:P/I:P/A:N","baseScore":2.6,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/17113","name":"http://www.securityfocus.com/bid/17113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Adobe Graphics Server / Document Server Remote Command Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015768","name":"http://securitytracker.com/id?1015768","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - Adobe Document Server Interactive Login Configuration Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/techdocs/332989.html","name":"http://www.adobe.com/support/techdocs/332989.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Security Advisory: Adobe Graphics Server and Adobe Document Server configuration security vulnerability - Support Knowledgebase","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/588","name":"http://securityreason.com/securityalert/588","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19229","name":"http://secunia.com/advisories/19229","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Adobe Document/Graphics Server File URI Resource Access - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1015769","name":"http://securitytracker.com/id?1015769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"SecurityTracker.com Archives - Adobe Graphics Server Interactive Login Configuration Lets Remote Users Execute Arbitrary Code","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/23924","name":"http://www.osvdb.org/23924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0956","name":"http://www.vupen.com/english/advisories/2006/0956","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/427730/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427730/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25247","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25247","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1182","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1182","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1182","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"document_server","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1182","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"document_server","cpe6":"6.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1182","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"graphics_server","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1182","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"graphics_server","cpe6":"2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1182","cve":"CVE-2006-1182","epss":"0.001810000","percentile":"0.398140000","score_date":"2026-04-17","updated_at":"2026-04-18 00:07:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:03:28.211Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"1015769","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015769"},{"name":"ADV-2006-0956","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0956"},{"name":"adobe-unauth-command-access(25247)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25247"},{"name":"17113","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17113"},{"name":"23924","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23924"},{"name":"20060315 Secunia Research: Adobe Document/Graphics Server File URI ResourceAccess","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427730/100/0/threaded"},{"name":"1015768","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015768"},{"name":"19229","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19229"},{"name":"588","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/588"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/techdocs/332989.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"1015769","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015769"},{"name":"ADV-2006-0956","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0956"},{"name":"adobe-unauth-command-access(25247)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25247"},{"name":"17113","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17113"},{"name":"23924","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23924"},{"name":"20060315 Secunia Research: Adobe Document/Graphics Server File URI ResourceAccess","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/427730/100/0/threaded"},{"name":"1015768","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015768"},{"name":"19229","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19229"},{"name":"588","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/588"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/techdocs/332989.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1182","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1015769","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015769"},{"name":"ADV-2006-0956","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0956"},{"name":"adobe-unauth-command-access(25247)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25247"},{"name":"17113","refsource":"BID","url":"http://www.securityfocus.com/bid/17113"},{"name":"23924","refsource":"OSVDB","url":"http://www.osvdb.org/23924"},{"name":"20060315 Secunia Research: Adobe Document/Graphics Server File URI ResourceAccess","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/427730/100/0/threaded"},{"name":"1015768","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015768"},{"name":"19229","refsource":"SECUNIA","url":"http://secunia.com/advisories/19229"},{"name":"588","refsource":"SREASON","url":"http://securityreason.com/securityalert/588"},{"name":"http://www.adobe.com/support/techdocs/332989.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/techdocs/332989.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1182","datePublished":"2006-03-16T01:00:00.000Z","dateReserved":"2006-03-12T00:00:00.000Z","dateUpdated":"2024-08-07T17:03:28.211Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-16 01:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:P/I:P/A:N","baseScore":2.6,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":1.9,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:document_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"5134806E-933A-420A-AE8B-F8A4491C21B4"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:document_server:6.0:*:*:*:*:*:*:*","matchCriteriaId":"2BD4A8E3-DF14-43DE-9B36-52A82B8E8869"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:graphics_server:2.0:*:*:*:*:*:*:*","matchCriteriaId":"2855B3E0-230A-407A-8B20-05BA79084C82"},{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:graphics_server:2.1:*:*:*:*:*:*:*","matchCriteriaId":"0404AFA3-6E18-40FA-9DA8-AD33F023CD49"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1182","Ordinal":"1","Title":"CVE-2006-1182","CVE":"CVE-2006-1182","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1182","Ordinal":"1","NoteData":"Adobe Graphics Server 2.0 and 2.1 (formerly AlterCast) and Adobe Document Server (ADS) 5.0 and 6.0 allows local users to read files with certain extensions or overwrite arbitrary files and execute code via a crafted SOAP request to the AlterCast web service in which the request uses the (1) saveContent or (2) saveOptimized ADS commands, or the (3) loadContent command.","Type":"Description","Title":"CVE-2006-1182"},{"CveYear":"2006","CveId":"1182","Ordinal":"2","NoteData":"2006-03-15","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1182","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}