CVE-2006-3063
Estado: ModificadaBaja (2.6)—
Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php.
CVSS
- Versión: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Puntuación base: 2.6
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.17%
- Percentil entre todas las CVEs puntuadas: 67
- Fecha de la puntuación: 7/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- NVD-CWE-Other
Referencias
- http://secunia.com/advisories/20764
- http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e
- http://www.securityfocus.com/bid/18582
- http://www.vupen.com/english/advisories/2006/2480
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27293
- http://secunia.com/advisories/20764
- http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e
- http://www.securityfocus.com/bid/18582
- http://www.vupen.com/english/advisories/2006/2480
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27293
JSON original (NVD)
Mostrar
{
"id": "CVE-2006-3063",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-06-19T10:02:00.000",
"references": [
{
"url": "http://secunia.com/advisories/20764",
"source": "cve@mitre.org"
},
{
"url": "http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/18582",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2480",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27293",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/20764",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.networkarea.ch/forum/topic.php?id=4&s=9106beea248ecd1a552439168ada227e",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/18582",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2480",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27293",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in myPHP Guestbook 1.x through 2.0.0-r1 and before 2.0.1 RC5 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) email, (3) homepage, (4) id, (5) name, and (6) text parameters in (a) index.php, the (7) comment, (8) email, (9) homepage, (10) number, (11) name, and (12) text parameters in (b) admin/guestbook.php, and the (13) email, (14) homepage, (15) icq, (16) name, and (17) text parameters in (c) admin/edit.php."
},
{
"lang": "es",
"value": "Múltiples vulnerabilidades de ejecución de comandos en sitios cruzaods (XSS) en myPHP Guestbook v1.x hasta la v2.0.0-r1 y antes de v2.0.1 RC5 permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) comment, (2) email, (3) homepage, (4) id, (5) name y (6) text in (a) index.php. También los parámetros (7) comment, (8) email, (9) homepage, (10) number, (11) name and (12) text en (b) admin/guestbook.php, y por último los parámetros (13) email, (14) homepage, (15) icq, (16) name y (17) text en edit.php."
}
],
"lastModified": "2026-06-16T22:26:19.357",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EEB92A38-41B3-4E8E-9396-340A4E9D01D2"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.8:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "47132A18-64DD-4DA3-9130-71E1BF689F99"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.8.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CE54EDCB-FDDD-4E4C-8AE4-2E2F2BA0B7F3"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.9:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E105BB6B-DFF8-40FF-8DE7-830908841263"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:1.9.2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5951406C-4460-42D2-B0AF-3BC5F0FD2738"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8419132F-D109-446C-AD91-8694888A699C"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0-r1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61D94A4B-8475-4BAA-8434-4B857E4CB188"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_alpha:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "97EE480B-D147-4C8B-AE90-70E6D9E166C0"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_beta:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1D1537F6-92E9-413F-89E0-EE5011DBBE1E"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5ADDFDFC-7AB4-4A7F-B75F-412A4165A5D5"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E3D6891-BF1F-4080-81E3-A5A75B54C16B"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "424B22E0-C10D-4413-9638-1C5F89F99902"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.0_rc4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B1DB7E63-09E1-4BF6-A826-F1072BD2D7B3"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_beta:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "324788C8-73BB-40FC-901D-C5DDA98541FE"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "094BDBC2-4BBE-491C-8311-952508C41AA0"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc2:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "181549D7-1F12-4483-AD6C-35DCC52EF22D"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "843ADF77-4300-44B0-8490-FB4B6C1FBAFC"
},
{
"criteria": "cpe:2.3:a:myphp_guestbook:myphp_guestbook:2.0.1_rc4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAB4501F-3C6E-4D56-B7A3-88D637137F1B"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}