« Volver al listado

CVE-2006-3063

Estado: ModificadaBaja (2.6)—

Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3063",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 2.6,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "LOW",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 4.9,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-19T10:02:00.000",
  "references": [
    {
      "url": "http://secunia.com/advisories/20764",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/18582",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2480",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27293",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20764",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/18582",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2480",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27293",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de ejecución de comandos en sitios cruzaods (XSS) en myPHP Guestbook v1.x hasta la v2.0.0-r1 y antes de v2.0.1 RC5 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) comment, (2) email, (3) homepage, (4) id, (5) name y (6) text in (a) index.php. También los parámetros (7) comment, (8) email, (9) homepage, (10) number, (11) name and (12) text en (b) admin/guestbook.php, y por último los parámetros (13) email, (14) homepage, (15) icq, (16) name y (17) text en edit.php."
    }
  ],
  "lastModified": "2026-06-16T22:26:19.357",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EEB92A38-41B3-4E8E-9396-340A4E9D01D2"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.8:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "47132A18-64DD-4DA3-9130-71E1BF689F99"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.8.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CE54EDCB-FDDD-4E4C-8AE4-2E2F2BA0B7F3"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E105BB6B-DFF8-40FF-8DE7-830908841263"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.9.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5951406C-4460-42D2-B0AF-3BC5F0FD2738"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8419132F-D109-446C-AD91-8694888A699C"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0-r1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "61D94A4B-8475-4BAA-8434-4B857E4CB188"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_alpha:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "97EE480B-D147-4C8B-AE90-70E6D9E166C0"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_beta:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1D1537F6-92E9-413F-89E0-EE5011DBBE1E"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ADDFDFC-7AB4-4A7F-B75F-412A4165A5D5"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8E3D6891-BF1F-4080-81E3-A5A75B54C16B"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "424B22E0-C10D-4413-9638-1C5F89F99902"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B1DB7E63-09E1-4BF6-A826-F1072BD2D7B3"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_beta:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "324788C8-73BB-40FC-901D-C5DDA98541FE"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "094BDBC2-4BBE-491C-8311-952508C41AA0"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "181549D7-1F12-4483-AD6C-35DCC52EF22D"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "843ADF77-4300-44B0-8490-FB4B6C1FBAFC"
            },
            {
              "criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BAB4501F-3C6E-4D56-B7A3-88D637137F1B"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}