CVE-2006-5791
Estado: ModificadaBaja (2.6)—
Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type or Category values in a New entry, which is not properly handled in an error message by the submit_elog function.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.37%
- Percentil entre todas las CVEs puntuadas: 71
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016
- http://secunia.com/advisories/22638
- http://secunia.com/advisories/23580
- http://www.debian.org/security/2006/dsa-1242
- http://www.securityfocus.com/bid/20881
- http://www.securityfocus.com/bid/20882
- http://www.vupen.com/english/advisories/2006/4315
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29986
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016
- http://secunia.com/advisories/22638
- http://secunia.com/advisories/23580
- http://www.debian.org/security/2006/dsa-1242
- http://www.securityfocus.com/bid/20881
- http://www.securityfocus.com/bid/20882
- http://www.vupen.com/english/advisories/2006/4315
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29986
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-5791",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-07T23:07:00.000",
"references": [
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/22638",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/23580",
"source": "cve@mitre.org"
},
{
"url": "http://www.debian.org/security/2006/dsa-1242",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20881",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20882",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4315",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29986",
"source": "cve@mitre.org"
},
{
"url": "http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=392016",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/22638",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/23580",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2006/dsa-1242",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20881",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20882",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/4315",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/29986",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in elogd.c in ELOG 2.6.2 and earlier allow remote attackers to inject arbitrary HTML or web script via (1) the filename for downloading, which is not quoted in an error message by the send_file_direct function, and (2) the Type or Category values in a New entry, which is not properly handled in an error message by the submit_elog function."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de secuencias de comandos en sitios cruzados (XSS) en elogd.c de ELOG 2.6.2 y anteriores permiten a atacantes remotos inyectar HTML o secuencias de comandos web de su elección mediante (1) el nombre de fichero para la bajada, el cual no es citado en un mensaje de error por la función send_file_direct, y (2) los valores tipo y categoría en una nueva entrada, que no son manejados adecuadamente en un mensaje de error por la función submit_elog."
}
],
"lastModified": "2026-06-16T22:31:53.020",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:stefan_ritt:elog_web_logbook:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72D613D0-64FD-4590-8087-C0A834C65586",
"versionEndIncluding": "2.6.2"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}