{"api_version":"1","generated_at":"2026-07-05T13:30:20+00:00","cve":"CVE-2006-0221","urls":{"html":"https://cve.report/CVE-2006-0221","api":"https://cve.report/api/cve/CVE-2006-0221.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0221","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0221"},"summary":{"title":"CVE-2006-0221","description":"SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-16 21:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/16231","name":"http://www.securityfocus.com/bid/16231","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"DDSN Interactive CM3CMS Admin Panel Index.ASP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24266","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24266","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/421941/100/0/threaded","name":"http://www.securityfocus.com/archive/1/421941/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/22696","name":"http://www.osvdb.org/22696","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0221","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0221","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"221","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"ddsn","cpe5":"cm3cms","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:34.030Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"16231","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16231"},{"name":"20060113 DDSN CMS Admin Panel SQL Injection Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/421941/100/0/threaded"},{"name":"22696","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/22696"},{"name":"cm3-login-sql-injection(24266)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24266"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"16231","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16231"},{"name":"20060113 DDSN CMS Admin Panel SQL Injection Vulnerability","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/421941/100/0/threaded"},{"name":"22696","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/22696"},{"name":"cm3-login-sql-injection(24266)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24266"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0221","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"16231","refsource":"BID","url":"http://www.securityfocus.com/bid/16231"},{"name":"20060113 DDSN CMS Admin Panel SQL Injection Vulnerability","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/421941/100/0/threaded"},{"name":"22696","refsource":"OSVDB","url":"http://www.osvdb.org/22696"},{"name":"cm3-login-sql-injection(24266)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24266"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0221","datePublished":"2006-01-16T21:00:00.000Z","dateReserved":"2006-01-16T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:34.030Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-16 21:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:ddsn:cm3cms:*:*:*:*:*:*:*:*","matchCriteriaId":"95F5F605-95A0-4659-BA4A-8E93D2240730"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"221","Ordinal":"1","Title":"CVE-2006-0221","CVE":"CVE-2006-0221","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"221","Ordinal":"1","NoteData":"SQL injection vulnerability in index.asp in the Admin Panel in Dragon Design Services Network (DDSN) cm3 content manager (CM3CMS) allows remote attackers to execute arbitrary SQL commands via the (1) username or (2) password.","Type":"Description","Title":"CVE-2006-0221"},{"CveYear":"2006","CveId":"221","Ordinal":"2","NoteData":"2006-01-16","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"221","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}