{"api_version":"1","generated_at":"2026-07-23T14:24:46+00:00","cve":"CVE-2006-6246","urls":{"html":"https://cve.report/CVE-2006-6246","api":"https://cve.report/api/cve/CVE-2006-6246.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6246","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6246"},"summary":{"title":"CVE-2006-6246","description":"Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-04 11:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/23176","name":"http://secunia.com/advisories/23176","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Photo Organizer Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://bugs.shaftnet.org/task/113","name":"http://bugs.shaftnet.org/task/113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"FS#113 : camera edit doesn't respect owner","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30577","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30577","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4766","name":"http://www.vupen.com/english/advisories/2006/4766","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/21351","name":"http://www.securityfocus.com/bid/21351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Photo Organizer Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://po.shaftnet.org/po_stable_changelog","name":"http://po.shaftnet.org/po_stable_changelog","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"po_stable_changelog    [Photo Organizer]","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6246","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6246","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6246","vulnerable":"1","versionEndIncluding":"2.32b","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"photo_organizer","cpe5":"photo_organizer","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:19:35.026Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://bugs.shaftnet.org/task/113"},{"name":"ADV-2006-4766","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4766"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://po.shaftnet.org/po_stable_changelog"},{"name":"23176","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23176"},{"name":"photoorganizer-auth-security-bypass(30577)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30577"},{"name":"21351","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21351"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://bugs.shaftnet.org/task/113"},{"name":"ADV-2006-4766","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4766"},{"tags":["x_refsource_CONFIRM"],"url":"http://po.shaftnet.org/po_stable_changelog"},{"name":"23176","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23176"},{"name":"photoorganizer-auth-security-bypass(30577)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30577"},{"name":"21351","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21351"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6246","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://bugs.shaftnet.org/task/113","refsource":"MISC","url":"http://bugs.shaftnet.org/task/113"},{"name":"ADV-2006-4766","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4766"},{"name":"http://po.shaftnet.org/po_stable_changelog","refsource":"CONFIRM","url":"http://po.shaftnet.org/po_stable_changelog"},{"name":"23176","refsource":"SECUNIA","url":"http://secunia.com/advisories/23176"},{"name":"photoorganizer-auth-security-bypass(30577)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30577"},{"name":"21351","refsource":"BID","url":"http://www.securityfocus.com/bid/21351"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6246","datePublished":"2006-12-04T11:00:00.000Z","dateReserved":"2006-12-03T00:00:00.000Z","dateUpdated":"2024-08-07T20:19:35.026Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-04 11:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:photo_organizer:photo_organizer:*:*:*:*:*:*:*:*","versionEndIncluding":"2.32b","matchCriteriaId":"8FA8F3F3-B81C-4CFF-B4E4-8CC06E6DBA0E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6246","Ordinal":"1","Title":"CVE-2006-6246","CVE":"CVE-2006-6246","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6246","Ordinal":"1","NoteData":"Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.","Type":"Description","Title":"CVE-2006-6246"},{"CveYear":"2006","CveId":"6246","Ordinal":"2","NoteData":"2006-12-04","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6246","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}