{"api_version":"1","generated_at":"2026-07-23T11:32:47+00:00","cve":"CVE-2006-0223","urls":{"html":"https://cve.report/CVE-2006-0223","api":"https://cve.report/api/cve/CVE-2006-0223.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0223","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0223"},"summary":{"title":"CVE-2006-0223","description":"Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via \"..\" (dot dot) sequences in the username field.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-01-16 21:03:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-22","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/22440","name":"http://www.osvdb.org/22440","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24137","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24137","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"503"},{"url":"http://www.securityfocus.com/bid/16235","name":"http://www.securityfocus.com/bid/16235","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"123 Flash Chat Server Arbitrary Remote File Creation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.123flashchat.com/flash-chat-server-v512.html","name":"http://www.123flashchat.com/flash-chat-server-v512.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Chatting and Sharing Goes Hand in Hand with PDF | The gogopdf Blog","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0198","name":"http://www.vupen.com/english/advisories/2006/0198","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18455","name":"http://secunia.com/advisories/18455","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - 123 Flash Chat Server Username Directory Traversal Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0223","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0223","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"223","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"topcmm_computing","cpe5":"123_flash_chat_server","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"223","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"topcmm_computing","cpe5":"123_flash_chat_server","cpe6":"5.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:25:34.023Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"18455","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18455"},{"name":"16235","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16235"},{"name":"ADV-2006-0198","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0198"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.123flashchat.com/flash-chat-server-v512.html"},{"name":"22440","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/22440"},{"name":"123flashchat-user-directory-traversal(24137)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24137"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-11T00:00:00.000Z","descriptions":[{"lang":"en","value":"Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via \"..\" (dot dot) sequences in the username field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"18455","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18455"},{"name":"16235","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16235"},{"name":"ADV-2006-0198","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0198"},{"tags":["x_refsource_MISC"],"url":"http://www.123flashchat.com/flash-chat-server-v512.html"},{"name":"22440","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/22440"},{"name":"123flashchat-user-directory-traversal(24137)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24137"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0223","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via \"..\" (dot dot) sequences in the username field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"18455","refsource":"SECUNIA","url":"http://secunia.com/advisories/18455"},{"name":"16235","refsource":"BID","url":"http://www.securityfocus.com/bid/16235"},{"name":"ADV-2006-0198","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0198"},{"name":"http://www.123flashchat.com/flash-chat-server-v512.html","refsource":"MISC","url":"http://www.123flashchat.com/flash-chat-server-v512.html"},{"name":"22440","refsource":"OSVDB","url":"http://www.osvdb.org/22440"},{"name":"123flashchat-user-directory-traversal(24137)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24137"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0223","datePublished":"2006-01-16T21:00:00.000Z","dateReserved":"2006-01-16T00:00:00.000Z","dateUpdated":"2024-08-07T16:25:34.023Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-01-16 21:03:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-22","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:N/I:P/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.0:*:*:*:*:*:*:*","matchCriteriaId":"797F15FA-6577-47F3-B342-EE950EF55475"},{"vulnerable":true,"criteria":"cpe:2.3:a:topcmm_computing:123_flash_chat_server:5.1:*:*:*:*:*:*:*","matchCriteriaId":"376197D6-056C-4991-9EE5-805549D8BDA9"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"223","Ordinal":"1","Title":"CVE-2006-0223","CVE":"CVE-2006-0223","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"223","Ordinal":"1","NoteData":"Directory traversal vulnerability in Shanghai TopCMM 123 Flash Chat Server Software 5.1 allows attackers to create or overwrite arbitrary files on the server via \"..\" (dot dot) sequences in the username field.","Type":"Description","Title":"CVE-2006-0223"},{"CveYear":"2006","CveId":"223","Ordinal":"2","NoteData":"2006-01-16","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"223","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}