{"api_version":"1","generated_at":"2026-07-23T09:33:49+00:00","cve":"CVE-2006-0782","urls":{"html":"https://cve.report/CVE-2006-0782","api":"https://cve.report/api/cve/CVE-2006-0782.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0782","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0782"},"summary":{"title":"CVE-2006-0782","description":"Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-02-19 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24692","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24692","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/426260/100/0/threaded","name":"http://www.securityfocus.com/archive/1/426260/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://evuln.com/vulns/81/summary.html","name":"http://evuln.com/vulns/81/summary.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"eVuln.com - PerlBlog Multiple Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/16707","name":"http://www.securityfocus.com/bid/16707","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PerlBlog Multiple Input Validation and Information Disclosure Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/508","name":"http://securityreason.com/securityalert/508","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/18924","name":"http://secunia.com/advisories/18924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"PerlBLOG Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0782","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0782","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"782","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"perlblog","cpe5":"perlblog","cpe6":"1.08","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"782","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"perlblog","cpe5":"perlblog","cpe6":"1.09","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"782","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"perlblog","cpe5":"perlblog","cpe6":"1.09b","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"782","cve":"CVE-2006-0782","epss":"0.055040000","percentile":"0.902490000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:48:56.078Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"20060227 [eVuln] PerlBlog Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/426260/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://evuln.com/vulns/81/summary.html"},{"name":"508","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/508"},{"name":"perlblog-weblog-command-execution(24692)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24692"},{"name":"18924","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18924"},{"name":"16707","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/16707"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-15T00:00:00.000Z","descriptions":[{"lang":"en","value":"Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"20060227 [eVuln] PerlBlog Multiple Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/426260/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://evuln.com/vulns/81/summary.html"},{"name":"508","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/508"},{"name":"perlblog-weblog-command-execution(24692)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24692"},{"name":"18924","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18924"},{"name":"16707","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/16707"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0782","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20060227 [eVuln] PerlBlog Multiple Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/426260/100/0/threaded"},{"name":"http://evuln.com/vulns/81/summary.html","refsource":"MISC","url":"http://evuln.com/vulns/81/summary.html"},{"name":"508","refsource":"SREASON","url":"http://securityreason.com/securityalert/508"},{"name":"perlblog-weblog-command-execution(24692)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/24692"},{"name":"18924","refsource":"SECUNIA","url":"http://secunia.com/advisories/18924"},{"name":"16707","refsource":"BID","url":"http://www.securityfocus.com/bid/16707"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0782","datePublished":"2006-02-19T11:00:00.000Z","dateReserved":"2006-02-19T00:00:00.000Z","dateUpdated":"2024-08-07T16:48:56.078Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-02-19 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":true,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:perlblog:perlblog:1.08:*:*:*:*:*:*:*","matchCriteriaId":"E9A7C823-EC74-44F3-9BC6-68F105A52D9C"},{"vulnerable":true,"criteria":"cpe:2.3:a:perlblog:perlblog:1.09:*:*:*:*:*:*:*","matchCriteriaId":"EF34B62B-C752-4167-AEBD-C28C9CC2FFC6"},{"vulnerable":true,"criteria":"cpe:2.3:a:perlblog:perlblog:1.09b:*:*:*:*:*:*:*","matchCriteriaId":"14572A2A-3D9D-438A-B331-FA95B10269BB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"782","Ordinal":"1","Title":"CVE-2006-0782","CVE":"CVE-2006-0782","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"782","Ordinal":"1","NoteData":"Unspecified vulnerability in weblog.pl in PerlBlog 1.09b and earlier allows remote attackers to create arbitrary files and possibly execute arbitrary code via unspecified attack vectors related to improper handling of (1) the reply parameter, possibly involving injection of (2) the name parameter and (3) the body parameter.","Type":"Description","Title":"CVE-2006-0782"},{"CveYear":"2006","CveId":"782","Ordinal":"2","NoteData":"2006-02-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"782","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}