CVE-2006-6246
Status: ModifiedHigh (7.5)—
Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations.
CVSS
- Version: 2.0
- Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P
- Base score: 7.5
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.67%
- Percentile among all scored CVEs: 76
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://bugs.shaftnet.org/task/113
- http://po.shaftnet.org/po_stable_changelog
- http://secunia.com/advisories/23176
- http://www.securityfocus.com/bid/21351
- http://www.vupen.com/english/advisories/2006/4766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30577
- http://bugs.shaftnet.org/task/113
- http://po.shaftnet.org/po_stable_changelog
- http://secunia.com/advisories/23176
- http://www.securityfocus.com/bid/21351
- http://www.vupen.com/english/advisories/2006/4766
- https://exchange.xforce.ibmcloud.com/vulnerabilities/30577
Raw JSON (NVD)
Show
{
"id": "CVE-2006-6246",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.5,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "LOW",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 10,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-12-04T11:28:00.000",
"references": [
{
"url": "http://bugs.shaftnet.org/task/113",
"source": "cve@mitre.org"
},
{
"url": "http://po.shaftnet.org/po_stable_changelog",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23176",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/21351",
"tags": [
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4766",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30577",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.shaftnet.org/task/113",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://po.shaftnet.org/po_stable_changelog",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23176",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/21351",
"tags": [
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4766",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/30577",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Photo Organizer 2.32b and earlier does not properly check the ownership of certain objects, which allows remote attackers to gain unauthorized access via vectors related to (1) camera del, (2) camera edit, (3) folder/album deletion, (4) photo.move, (5) content.indexer, (6) folder.content, and possibly other operations."
},
{
"lang": "es",
"value": "Photo Organizer 2.32b y anteriores no comprueban adecuadamente la propiedad de ciertos objetos, lo cual permite a atacantes remotos obtener acceso no autorizado a través de vectores relacionados con (1) borrado de cámara, (2) edición de cámara, (3) borrado de carpeta/álbum, (4) mover foto (photo.move), (5) indizador de contenido (content.indexer), (6) contenido de carpeta (folder.content), y posiblemente otras operaciones."
}
],
"lastModified": "2026-06-16T22:32:45.287",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:photo_organizer:photo_organizer:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8FA8F3F3-B81C-4CFF-B4E4-8CC06E6DBA0E",
"versionEndIncluding": "2.32b"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}