{"api_version":"1","generated_at":"2026-07-23T07:11:15+00:00","cve":"CVE-2006-0201","urls":{"html":"https://cve.report/CVE-2006-0201","api":"https://cve.report/api/cve/CVE-2006-0201.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0201","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0201"},"summary":{"title":"CVE-2006-0201","description":"Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-13 23:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml","name":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/22378","name":"http://www.osvdb.org/22378","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0183","name":"http://www.vupen.com/english/advisories/2006/0183","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18444","name":"http://secunia.com/advisories/18444","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"PHP Toolkit for PayPal Payment Bypass and Exposure of Transactions - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16218","name":"http://www.securityfocus.com/bid/16218","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PHP Toolkit for PayPal IPN_success.PHP Logfile Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/421739","name":"http://www.securityfocus.com/archive/1/421739","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0201","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0201","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"201","vulnerable":"1","versionEndIncluding":"0.50","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"paypal","cpe5":"php_toolkit","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:33.971Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"},{"name":"18444","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18444"},{"name":"ADV-2006-0183","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0183"},{"name":"22378","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/22378"},{"name":"16218","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16218"},{"name":"20060112 Multiple PHP Toolkit for PayPal Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/421739"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-01-20T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"},{"name":"18444","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18444"},{"name":"ADV-2006-0183","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0183"},{"name":"22378","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/22378"},{"name":"16218","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16218"},{"name":"20060112 Multiple PHP Toolkit for PayPal Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/421739"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0201","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml","refsource":"MISC","url":"http://www.uinc.ru/articles/vuln/ptpaypal050.shtml"},{"name":"18444","refsource":"SECUNIA","url":"http://secunia.com/advisories/18444"},{"name":"ADV-2006-0183","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0183"},{"name":"22378","refsource":"OSVDB","url":"http://www.osvdb.org/22378"},{"name":"16218","refsource":"BID","url":"http://www.securityfocus.com/bid/16218"},{"name":"20060112 Multiple PHP Toolkit for PayPal Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/421739"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0201","datePublished":"2006-01-13T23:00:00.000Z","dateReserved":"2006-01-13T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:33.971Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-13 23:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:paypal:php_toolkit:*:*:*:*:*:*:*:*","versionEndIncluding":"0.50","matchCriteriaId":"50D66514-FAC2-4E1B-AF92-4FEAE982EF8A"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"201","Ordinal":"1","Title":"CVE-2006-0201","CVE":"CVE-2006-0201","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"201","Ordinal":"1","NoteData":"Dave Nielsen and Patrick Breitenbach PayPal Web Services (aka PHP Toolkit) 0.50, and possibly earlier versions, allows remote attackers to enter false payment entries into the log file via HTTP POST requests to ipn_success.php.","Type":"Description","Title":"CVE-2006-0201"},{"CveYear":"2006","CveId":"201","Ordinal":"2","NoteData":"2006-01-13","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"201","Ordinal":"3","NoteData":"2006-01-20","Type":"Other","Title":"Modified"}]}}}