{"api_version":"1","generated_at":"2026-07-23T14:50:30+00:00","cve":"CVE-2006-1202","urls":{"html":"https://cve.report/CVE-2006-1202","api":"https://cve.report/api/cve/CVE-2006-1202.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1202","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1202"},"summary":{"title":"CVE-2006-1202","description":"Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-14 01:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/0897","name":"http://www.vupen.com/english/advisories/2006/0897","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://notlegal.ws/textfilebbmessanger.txt","name":"http://notlegal.ws/textfilebbmessanger.txt","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["URL Repurposed"],"title":"WEBSITE.WS - Your Internet Address For Life™","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25091","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25091","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17029","name":"http://www.securityfocus.com/bid/17029","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TextfileBB Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1015744","name":"http://securitytracker.com/id?1015744","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityTracker.com Archives - TextfileBB Input Validation Flaw in 'messanger.php' Lets Remote Users Conduct Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/427081/100/0/threaded","name":"http://www.securityfocus.com/archive/1/427081/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19149","name":"http://secunia.com/advisories/19149","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"textfileBB \"messanger.php\" Cross-Site Scripting Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1202","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1202","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1202","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jcink.com","cpe5":"textfilebb","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1202","cve":"CVE-2006-1202","epss":"0.008640000","percentile":"0.751370000","score_date":"2026-04-17","updated_at":"2026-04-18 00:07:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:03:28.233Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17029","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17029"},{"name":"ADV-2006-0897","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0897"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://notlegal.ws/textfilebbmessanger.txt"},{"name":"20060308 textfileBB <= 1.0 Multiple XSS","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/427081/100/0/threaded"},{"name":"textbb-messanger-xss(25091)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25091"},{"name":"1015744","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1015744"},{"name":"19149","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19149"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-08T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17029","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17029"},{"name":"ADV-2006-0897","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0897"},{"tags":["x_refsource_MISC"],"url":"http://notlegal.ws/textfilebbmessanger.txt"},{"name":"20060308 textfileBB <= 1.0 Multiple XSS","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/427081/100/0/threaded"},{"name":"textbb-messanger-xss(25091)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25091"},{"name":"1015744","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1015744"},{"name":"19149","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19149"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1202","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17029","refsource":"BID","url":"http://www.securityfocus.com/bid/17029"},{"name":"ADV-2006-0897","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0897"},{"name":"http://notlegal.ws/textfilebbmessanger.txt","refsource":"MISC","url":"http://notlegal.ws/textfilebbmessanger.txt"},{"name":"20060308 textfileBB <= 1.0 Multiple XSS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/427081/100/0/threaded"},{"name":"textbb-messanger-xss(25091)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25091"},{"name":"1015744","refsource":"SECTRACK","url":"http://securitytracker.com/id?1015744"},{"name":"19149","refsource":"SECUNIA","url":"http://secunia.com/advisories/19149"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1202","datePublished":"2006-03-14T01:00:00.000Z","dateReserved":"2006-03-14T00:00:00.000Z","dateUpdated":"2024-08-07T17:03:28.233Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-14 01:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jcink.com:textfilebb:1.0:*:*:*:*:*:*:*","matchCriteriaId":"F479BDC3-32EE-44C8-90FD-A7E71B0B8BF8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1202","Ordinal":"1","Title":"CVE-2006-1202","CVE":"CVE-2006-1202","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1202","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in textfileBB 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) mess and (2) user parameters in messanger.php, possibly requiring a URL encoded value.","Type":"Description","Title":"CVE-2006-1202"},{"CveYear":"2006","CveId":"1202","Ordinal":"2","NoteData":"2006-03-13","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1202","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}