{"api_version":"1","generated_at":"2026-07-23T09:56:18+00:00","cve":"CVE-2006-0683","urls":{"html":"https://cve.report/CVE-2006-0683","api":"https://cve.report/api/cve/CVE-2006-0683.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0683","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0683"},"summary":{"title":"CVE-2006-0683","description":"Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-02-15 00:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/424816/100/0/threaded","name":"http://www.securityfocus.com/archive/1/424816/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0534","name":"http://www.vupen.com/english/advisories/2006/0534","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16600","name":"http://www.securityfocus.com/bid/16600","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Virtual Hosting Control System Multiple Input Validation And Access Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/18799","name":"http://secunia.com/advisories/18799","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"VHCS Security Issue and Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24664","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24664","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt","name":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0683","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0683","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"683","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"virtual_hosting_control_system","cpe5":"virtual_hosting_control_system","cpe6":"2.4.7.1_patch_v.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"683","vulnerable":"1","versionEndIncluding":"2.4.6.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"virtual_hosting_control_system","cpe5":"virtual_hosting_control_system","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"683","cve":"CVE-2006-0683","epss":"0.005720000","percentile":"0.686990000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:41:29.298Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"vhcs-admin-xss(24664)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24664"},{"name":"18799","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18799"},{"name":"20060211 RS-2006-1: Multiple flaws in VHCS 2.x","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/424816/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"},{"name":"16600","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16600"},{"name":"ADV-2006-0534","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0534"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-13T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-19T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"vhcs-admin-xss(24664)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24664"},{"name":"18799","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18799"},{"name":"20060211 RS-2006-1: Multiple flaws in VHCS 2.x","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/424816/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"},{"name":"16600","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16600"},{"name":"ADV-2006-0534","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0534"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0683","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"vhcs-admin-xss(24664)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24664"},{"name":"18799","refsource":"SECUNIA","url":"http://secunia.com/advisories/18799"},{"name":"20060211 RS-2006-1: Multiple flaws in VHCS 2.x","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/424816/100/0/threaded"},{"name":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt","refsource":"MISC","url":"http://www.rs-labs.com/adv/RS-Labs-Advisory-2006-1.txt"},{"name":"16600","refsource":"BID","url":"http://www.securityfocus.com/bid/16600"},{"name":"ADV-2006-0534","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0534"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0683","datePublished":"2006-02-15T00:00:00.000Z","dateReserved":"2006-02-14T00:00:00.000Z","dateUpdated":"2024-08-07T16:41:29.298Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-02-15 00:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:*:*:*:*:*:*:*:*","versionEndIncluding":"2.4.6.2","matchCriteriaId":"D3725CCD-A9A9-48AD-9D5A-0E1F33C92529"},{"vulnerable":true,"criteria":"cpe:2.3:a:virtual_hosting_control_system:virtual_hosting_control_system:2.4.7.1_patch_v.1:*:*:*:*:*:*:*","matchCriteriaId":"814F008E-1E3C-4832-AF78-1945C167B61D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"683","Ordinal":"1","Title":"CVE-2006-0683","CVE":"CVE-2006-0683","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"683","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Virtual Hosting Control System (VHCS) 2.4.7.1 with v.1 patch and earlier allows remote attackers to inject arbitrary web script or HTML via the username, which is recorded in a log file but not properly handled when the administrator uses the admin log utility to read the log file.","Type":"Description","Title":"CVE-2006-0683"},{"CveYear":"2006","CveId":"683","Ordinal":"2","NoteData":"2006-02-14","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"683","Ordinal":"3","NoteData":"2018-10-19","Type":"Other","Title":"Modified"}]}}}