{"api_version":"1","generated_at":"2026-07-23T12:26:03+00:00","cve":"CVE-2006-1144","urls":{"html":"https://cve.report/CVE-2006-1144","api":"https://cve.report/api/cve/CVE-2006-1144.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1144","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1144"},"summary":{"title":"CVE-2006-1144","description":"Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-10 11:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25105","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25105","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/23757","name":"http://www.osvdb.org/23757","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/23758","name":"http://www.osvdb.org/23758","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/0886","name":"http://www.vupen.com/english/advisories/2006/0886","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/426931/100/0/threaded","name":"http://www.securityfocus.com/archive/1/426931/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19155","name":"http://secunia.com/advisories/19155","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"HitHost Cross-Site Scripting and Directory Deletion - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17025","name":"http://www.securityfocus.com/bid/17025","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Daverave HitHost Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1144","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1144","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1144","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"david_ravenscroft","cpe5":"hithost","cpe6":"1.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1144","cve":"CVE-2006-1144","epss":"0.013550000","percentile":"0.801530000","score_date":"2026-04-17","updated_at":"2026-04-18 00:07:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:03:27.495Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"hithost-viewuser-deleteuser-xss(25105)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25105"},{"name":"23758","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23758"},{"name":"17025","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17025"},{"name":"19155","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19155"},{"name":"20060306 histhost v1.0.0 xss and possible rmdir","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/426931/100/0/threaded"},{"name":"23757","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/23757"},{"name":"ADV-2006-0886","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0886"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"hithost-viewuser-deleteuser-xss(25105)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25105"},{"name":"23758","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23758"},{"name":"17025","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17025"},{"name":"19155","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19155"},{"name":"20060306 histhost v1.0.0 xss and possible rmdir","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/426931/100/0/threaded"},{"name":"23757","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/23757"},{"name":"ADV-2006-0886","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0886"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1144","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"hithost-viewuser-deleteuser-xss(25105)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25105"},{"name":"23758","refsource":"OSVDB","url":"http://www.osvdb.org/23758"},{"name":"17025","refsource":"BID","url":"http://www.securityfocus.com/bid/17025"},{"name":"19155","refsource":"SECUNIA","url":"http://secunia.com/advisories/19155"},{"name":"20060306 histhost v1.0.0 xss and possible rmdir","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/426931/100/0/threaded"},{"name":"23757","refsource":"OSVDB","url":"http://www.osvdb.org/23757"},{"name":"ADV-2006-0886","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0886"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1144","datePublished":"2006-03-10T11:00:00.000Z","dateReserved":"2006-03-10T00:00:00.000Z","dateUpdated":"2024-08-07T17:03:27.495Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-10 11:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:david_ravenscroft:hithost:1.0.0:*:*:*:*:*:*:*","matchCriteriaId":"BEE922AA-03DA-448A-8766-300876E73DB6"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1144","Ordinal":"1","Title":"CVE-2006-1144","CVE":"CVE-2006-1144","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1144","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.","Type":"Description","Title":"CVE-2006-1144"},{"CveYear":"2006","CveId":"1144","Ordinal":"2","NoteData":"2006-03-10","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1144","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}