{"api_version":"1","generated_at":"2026-07-23T13:16:56+00:00","cve":"CVE-2006-0919","urls":{"html":"https://cve.report/CVE-2006-0919","api":"https://cve.report/api/cve/CVE-2006-0919.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-0919","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-0919"},"summary":{"title":"CVE-2006-0919","description":"SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-02-28 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/18993","name":"http://secunia.com/advisories/18993","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Oi! Email Marketing System Username SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt","name":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/23462","name":"http://www.osvdb.org/23462","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/425924/100/0/threaded","name":"http://www.securityfocus.com/archive/1/425924/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/0718","name":"http://www.vupen.com/english/advisories/2006/0718","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-0919","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-0919","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"919","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"oi","cpe5":"email_marketing_system","cpe6":"3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"919","cve":"CVE-2006-0919","epss":"0.007430000","percentile":"0.730220000","score_date":"2026-04-16","updated_at":"2026-04-17 00:09:25"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T16:56:15.655Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"23462","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23462"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt"},{"name":"20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/425924/100/0/threaded"},{"name":"18993","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/18993"},{"name":"ADV-2006-0718","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0718"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-02-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"23462","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23462"},{"tags":["x_refsource_MISC"],"url":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt"},{"name":"20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/425924/100/0/threaded"},{"name":"18993","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/18993"},{"name":"ADV-2006-0718","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0718"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-0919","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"23462","refsource":"OSVDB","url":"http://www.osvdb.org/23462"},{"name":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt","refsource":"MISC","url":"http://www.h4cky0u.org/advisories/HYSA-2006-003-oi-email.txt"},{"name":"20060223 HYSA-2006-003 Oi! Email Marketing 3.0 SQL Injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/425924/100/0/threaded"},{"name":"18993","refsource":"SECUNIA","url":"http://secunia.com/advisories/18993"},{"name":"ADV-2006-0718","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0718"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-0919","datePublished":"2006-02-28T11:00:00.000Z","dateReserved":"2006-02-28T00:00:00.000Z","dateUpdated":"2024-08-07T16:56:15.655Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-02-28 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:oi:email_marketing_system:3.0:*:*:*:*:*:*:*","matchCriteriaId":"B2388725-17A8-48A8-BB54-DD696C5767AE"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"919","Ordinal":"1","Title":"CVE-2006-0919","CVE":"CVE-2006-0919","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"919","Ordinal":"1","NoteData":"SQL injection vulnerability in index.php (aka the login page) in Oi! Email Marketing System 3.0 (aka Oi! 3) allows remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields.","Type":"Description","Title":"CVE-2006-0919"},{"CveYear":"2006","CveId":"919","Ordinal":"2","NoteData":"2006-02-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"919","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}