CVE-2006-5717
Status: ModifiedMedium (4.3)—
Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files.
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:N/I:P/A:N
- Base score: 4.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.16%
- Percentile among all scored CVEs: 66
- Score date: 10/9/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://securityreason.com/securityalert/1815
- http://www.armorize.com/resources/vulnerability.php?Keyword=Armorize-ADV-2006-0008
- http://www.securityfocus.com/archive/1/450245/100/0/threaded
- http://www.securityfocus.com/bid/20851
- http://securityreason.com/securityalert/1815
- http://www.armorize.com/resources/vulnerability.php?Keyword=Armorize-ADV-2006-0008
- http://www.securityfocus.com/archive/1/450245/100/0/threaded
- http://www.securityfocus.com/bid/20851
Raw JSON (NVD)
Show
{
"id": "CVE-2006-5717",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-11-04T01:07:00.000",
"references": [
{
"url": "http://securityreason.com/securityalert/1815",
"source": "cve@mitre.org"
},
{
"url": "http://www.armorize.com/resources/vulnerability.php?Keyword=Armorize-ADV-2006-0008",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/450245/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/20851",
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1815",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.armorize.com/resources/vulnerability.php?Keyword=Armorize-ADV-2006-0008",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/450245/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/20851",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Multiple cross-site scripting (XSS) vulnerabilities in Zend Google Data Client Library (ZendGData) Preview 0.2.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) basedemo.php and (2) calenderdemo.php in samples/, and other unspecified files."
},
{
"lang": "es",
"value": "Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en Zend Google Data Client Library (ZendGData) Preview 0.2.0 permite a un atacante remoto inyectar secuencias de comandos web o HMTL a través de parámetro no especificados en (1)basedemo.php y (2) calenderdemo.php en samples/, y otros ficheros no especificados."
}
],
"lastModified": "2026-06-16T22:31:42.363",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:zend:zend_google_data_client_library_preview:0.2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BF531DD2-320E-47A1-9340-9BE4849F7E50"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}