{"api_version":"1","generated_at":"2026-07-23T10:25:55+00:00","cve":"CVE-2006-0136","urls":{"html":"https://cve.report/CVE-2006-0136","api":"https://cve.report/api/cve/CVE-2006-0136.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0136","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0136"},"summary":{"title":"CVE-2006-0136","description":"Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-09 11:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/420669/100/0/threaded","name":"http://www.securityfocus.com/archive/1/420669/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://evuln.com/vulns/7/exploit.html","name":"http://evuln.com/vulns/7/exploit.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"eVuln.com - Chimera Web Portal System Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://evuln.com/vulns/7/summary.html","name":"http://evuln.com/vulns/7/summary.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"eVuln.com - Chimera Web Portal System Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16113","name":"http://www.securityfocus.com/bid/16113","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Chimera Web Portal Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0025","name":"http://www.vupen.com/english/advisories/2006/0025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0136","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0136","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"136","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"phanatic_softwares","cpe5":"chimera_web_portal","cpe6":"0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:33.945Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://evuln.com/vulns/7/exploit.html"},{"name":"ADV-2006-0025","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0025"},{"name":"20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/420669/100/0/threaded"},{"name":"16113","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16113"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://evuln.com/vulns/7/summary.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://evuln.com/vulns/7/exploit.html"},{"name":"ADV-2006-0025","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0025"},{"name":"20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/420669/100/0/threaded"},{"name":"16113","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16113"},{"tags":["x_refsource_MISC"],"url":"http://evuln.com/vulns/7/summary.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0136","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://evuln.com/vulns/7/exploit.html","refsource":"MISC","url":"http://evuln.com/vulns/7/exploit.html"},{"name":"ADV-2006-0025","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0025"},{"name":"20060101 [eVuln] Chimera Web Portal System Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/420669/100/0/threaded"},{"name":"16113","refsource":"BID","url":"http://www.securityfocus.com/bid/16113"},{"name":"http://evuln.com/vulns/7/summary.html","refsource":"MISC","url":"http://evuln.com/vulns/7/summary.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0136","datePublished":"2006-01-09T11:00:00.000Z","dateReserved":"2006-01-09T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:33.945Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-09 11:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:phanatic_softwares:chimera_web_portal:0.2:*:*:*:*:*:*:*","matchCriteriaId":"1E61E31B-1779-4771-A24A-D23892998723"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"136","Ordinal":"1","Title":"CVE-2006-0136","CVE":"CVE-2006-0136","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"136","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the guestbook module in modules.php in Phanatic Softwares Chimera Web Portal System 0.2 allow remote attackers to inject arbitrary web script or HTML via the (1) comment_poster, (2) comment_poster_email, (3) comment_poster_homepage, and (4) comment_text parameters.","Type":"Description","Title":"CVE-2006-0136"},{"CveYear":"2006","CveId":"136","Ordinal":"2","NoteData":"2006-01-09","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"136","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}