{"api_version":"1","generated_at":"2026-07-23T15:27:55+00:00","cve":"CVE-2006-1287","urls":{"html":"https://cve.report/CVE-2006-1287","api":"https://cve.report/api/cve/CVE-2006-1287.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1287","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1287"},"summary":{"title":"CVE-2006-1287","description":"Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-19 23:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/0861","name":"http://www.vupen.com/english/advisories/2006/0861","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19141","name":"http://secunia.com/advisories/19141","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Invision Power Board Cross-Site Scripting and SQL Injection Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://forums.invisionpower.com/index.php?showtopic=206790","name":"http://forums.invisionpower.com/index.php?showtopic=206790","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"IPB 2.x.x (30/1/06) Security Update - Invision Power Services","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1287","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1287","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1287","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"invision_power_services","cpe5":"invision_power_board","cpe6":"2.0.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1287","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"invision_power_services","cpe5":"invision_power_board","cpe6":"2.1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1287","cve":"CVE-2006-1287","epss":"0.004230000","percentile":"0.621500000","score_date":"2026-04-17","updated_at":"2026-04-18 00:07:15"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:03:28.853Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19141","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19141"},{"name":"ADV-2006-0861","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/0861"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://forums.invisionpower.com/index.php?showtopic=206790"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-01-30T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-04-18T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19141","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19141"},{"name":"ADV-2006-0861","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/0861"},{"tags":["x_refsource_CONFIRM"],"url":"http://forums.invisionpower.com/index.php?showtopic=206790"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1287","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19141","refsource":"SECUNIA","url":"http://secunia.com/advisories/19141"},{"name":"ADV-2006-0861","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/0861"},{"name":"http://forums.invisionpower.com/index.php?showtopic=206790","refsource":"CONFIRM","url":"http://forums.invisionpower.com/index.php?showtopic=206790"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1287","datePublished":"2006-03-19T23:00:00.000Z","dateReserved":"2006-03-19T00:00:00.000Z","dateUpdated":"2024-08-07T17:03:28.853Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-19 23:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:invision_power_services:invision_power_board:2.0.4:*:*:*:*:*:*:*","matchCriteriaId":"6E24336F-BD4C-4596-8FFE-9D53AB802BB1"},{"vulnerable":true,"criteria":"cpe:2.3:a:invision_power_services:invision_power_board:2.1.4:*:*:*:*:*:*:*","matchCriteriaId":"67ED0140-7137-4F8D-AEA1-53251D4D4273"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1287","Ordinal":"1","Title":"CVE-2006-1287","CVE":"CVE-2006-1287","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1287","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in Invision Power Board (IPB) 2.0.4 and 2.1.4 before 20060130 allows remote attackers to steal cookies and probably conduct other activities when the victim is using Internet Explorer.","Type":"Description","Title":"CVE-2006-1287"},{"CveYear":"2006","CveId":"1287","Ordinal":"2","NoteData":"2006-03-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1287","Ordinal":"3","NoteData":"2006-04-18","Type":"Other","Title":"Modified"}]}}}