{"api_version":"1","generated_at":"2026-07-23T10:47:10+00:00","cve":"CVE-2006-2046","urls":{"html":"https://cve.report/CVE-2006-2046","api":"https://cve.report/api/cve/CVE-2006-2046.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2046","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2046"},"summary":{"title":"CVE-2006-2046","description":"Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-26 20:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.4","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/24962","name":"http://www.osvdb.org/24962","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1513","name":"http://www.vupen.com/english/advisories/2006/1513","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19812","name":"http://secunia.com/advisories/19812","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cartweaver Multiple SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.exploit-db.com/exploits/4264","name":"https://www.exploit-db.com/exploits/4264","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CartWeaver (Details.cfm ProdID) Remote SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17941","name":"http://www.securityfocus.com/bid/17941","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Application Dynamics Cartweaver ColdFusion SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes","name":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Yacoblog: CartWeaver SQL Injection holes","mime":"application/octet-stream","httpstatus":"502","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html","name":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Cartweaver ColdFusion vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25210","name":"http://www.securityfocus.com/bid/25210","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Cartweaver Details.CFM SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26060","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26060","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24961","name":"http://www.osvdb.org/24961","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2046","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2046","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2046","vulnerable":"1","versionEndIncluding":"2.16.11","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"application_dynamics","cpe5":"cartweaver_coldfusion","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"2046","cve":"CVE-2006-2046","epss":"0.036410000","percentile":"0.878660000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:35:31.305Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"cartweaver-multiple-sql-injection(26060)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26060"},{"name":"ADV-2006-1513","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1513"},{"name":"25210","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25210"},{"name":"24962","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24962"},{"name":"4264","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"https://www.exploit-db.com/exploits/4264"},{"name":"19812","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19812"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"},{"name":"17941","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17941"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes"},{"name":"24961","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24961"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-10-10T00:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"cartweaver-multiple-sql-injection(26060)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26060"},{"name":"ADV-2006-1513","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1513"},{"name":"25210","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25210"},{"name":"24962","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24962"},{"name":"4264","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"https://www.exploit-db.com/exploits/4264"},{"name":"19812","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19812"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"},{"name":"17941","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17941"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes"},{"name":"24961","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24961"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2046","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cartweaver-multiple-sql-injection(26060)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26060"},{"name":"ADV-2006-1513","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1513"},{"name":"25210","refsource":"BID","url":"http://www.securityfocus.com/bid/25210"},{"name":"24962","refsource":"OSVDB","url":"http://www.osvdb.org/24962"},{"name":"4264","refsource":"EXPLOIT-DB","url":"https://www.exploit-db.com/exploits/4264"},{"name":"19812","refsource":"SECUNIA","url":"http://secunia.com/advisories/19812"},{"name":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/04/cartweaver-coldfusion-vuln.html"},{"name":"17941","refsource":"BID","url":"http://www.securityfocus.com/bid/17941"},{"name":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes","refsource":"CONFIRM","url":"http://www.techfeed.net/blog/index.cfm/2006/4/26/cartweaver-holes"},{"name":"24961","refsource":"OSVDB","url":"http://www.osvdb.org/24961"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-2046","datePublished":"2006-04-26T20:00:00.000Z","dateReserved":"2006-04-26T00:00:00.000Z","dateUpdated":"2024-08-07T17:35:31.305Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-26 20:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:N","baseScore":6.4,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:application_dynamics:cartweaver_coldfusion:*:*:*:*:*:*:*:*","versionEndIncluding":"2.16.11","matchCriteriaId":"38FCE38F-809E-411A-848E-5D562B2DE8E1"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2046","Ordinal":"1","Title":"CVE-2006-2046","CVE":"CVE-2006-2046","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2046","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) category and (2) keywords parameters in (a) Results.cfm, and the (3) ProdID parameter in (b) Details.cfm.","Type":"Description","Title":"CVE-2006-2046"},{"CveYear":"2006","CveId":"2046","Ordinal":"2","NoteData":"2006-04-26","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2046","Ordinal":"3","NoteData":"2017-10-09","Type":"Other","Title":"Modified"}]}}}