{"api_version":"1","generated_at":"2026-07-23T08:58:36+00:00","cve":"CVE-2006-1627","urls":{"html":"https://cve.report/CVE-2006-1627","api":"https://cve.report/api/cve/CVE-2006-1627.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1627","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1627"},"summary":{"title":"CVE-2006-1627","description":"Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-13 18:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/17500","name":"http://www.securityfocus.com/bid/17500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Document Server for Reader Extensions Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015905","name":"http://securitytracker.com/id?1015905","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Adobe Document Server May Disclose Authentication Credentials to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/secunia_research/2005-68/advisory/","name":"http://secunia.com/secunia_research/2005-68/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Vulnerability and Virus Information - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1342","name":"http://www.vupen.com/english/advisories/2006/1342","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/430869/100/0/threaded","name":"http://www.securityfocus.com/archive/1/430869/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25769","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25769","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.adobe.com/support/techdocs/322699.html","name":"http://www.adobe.com/support/techdocs/322699.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Security Advisory: Adobe Document Server for Reader Extensions authentication vulnerability - Support Knowledgebase","mime":"text/xml","httpstatus":"404","archivestatus":"200"},{"url":"http://secunia.com/advisories/15924","name":"http://secunia.com/advisories/15924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Adobe Document Server for Reader Extensions Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1627","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1627","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1627","vulnerable":"1","versionEndIncluding":"6.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"adobe","cpe5":"acrobat_reader","cpe6":"*","cpe7":"*","cpe8":"reader_extensions","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1627","cve":"CVE-2006-1627","epss":"0.042740000","percentile":"0.900590000","score_date":"2026-07-22","updated_at":"2026-07-23 00:09:35"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:48.645Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/430869/100/0/threaded"},{"name":"adobe-access-control-bypass(25769)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25769"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.adobe.com/support/techdocs/322699.html"},{"name":"1015905","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015905"},{"name":"15924","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/15924"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2005-68/advisory/"},{"name":"ADV-2006-1342","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1342"},{"name":"17500","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17500"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/430869/100/0/threaded"},{"name":"adobe-access-control-bypass(25769)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25769"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.adobe.com/support/techdocs/322699.html"},{"name":"1015905","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015905"},{"name":"15924","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/15924"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2005-68/advisory/"},{"name":"ADV-2006-1342","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1342"},{"name":"17500","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17500"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1627","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060413 Secunia Research: Adobe Document Server for Reader ExtensionsMultiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/430869/100/0/threaded"},{"name":"adobe-access-control-bypass(25769)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25769"},{"name":"http://www.adobe.com/support/techdocs/322699.html","refsource":"CONFIRM","url":"http://www.adobe.com/support/techdocs/322699.html"},{"name":"1015905","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015905"},{"name":"15924","refsource":"SECUNIA","url":"http://secunia.com/advisories/15924"},{"name":"http://secunia.com/secunia_research/2005-68/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2005-68/advisory/"},{"name":"ADV-2006-1342","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1342"},{"name":"17500","refsource":"BID","url":"http://www.securityfocus.com/bid/17500"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1627","datePublished":"2006-04-13T18:00:00.000Z","dateReserved":"2006-04-05T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:48.645Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-13 18:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:adobe:acrobat_reader:*:*:reader_extensions:*:*:*:*:*","versionEndIncluding":"6.0","matchCriteriaId":"AF3D78AA-2446-4652-92EA-2DCB65B84A87"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1627","Ordinal":"1","Title":"CVE-2006-1627","CVE":"CVE-2006-1627","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1627","Ordinal":"1","NoteData":"Adobe Document Server for Reader Extensions 6.0 does not provide proper access control, which allows remote authenticated users to perform privileged actions by modifying the (1) actionID and (2) pageID parameters.  NOTE: due to an error during reservation, this identifier was inadvertently associated with multiple issues.  Other CVE identifiers have been assigned to handle other problems that are covered by the same disclosure.","Type":"Description","Title":"CVE-2006-1627"},{"CveYear":"2006","CveId":"1627","Ordinal":"2","NoteData":"2006-04-13","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1627","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}