{"api_version":"1","generated_at":"2026-04-23T10:56:50+00:00","cve":"CVE-2006-1394","urls":{"html":"https://cve.report/CVE-2006-1394","api":"https://cve.report/api/cve/CVE-2006-1394.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1394","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1394"},"summary":{"title":"CVE-2006-1394","description":"Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-26 23:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/24520","name":"http://www.osvdb.org/24520","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://pubcookie.org/news/20060306-apps-secadv.html","name":"http://pubcookie.org/news/20060306-apps-secadv.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"March 6, 2006: Pubcookie application server security advisory","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17221","name":"http://www.securityfocus.com/bid/17221","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pubcookies Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.kb.cert.org/vuls/id/314540","name":"http://www.kb.cert.org/vuls/id/314540","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory","US Government Resource"],"title":"US-CERT Vulnerability Note VU#314540","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19348","name":"http://secunia.com/advisories/19348","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Pubcookie Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1394","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1394","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.0.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.1.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.2.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.2.1a","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"university_of_washington","cpe5":"pubcookie","cpe6":"3.3.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1394","cve":"CVE-2006-1394","epss":"0.019340000","percentile":"0.834340000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:20.922Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://pubcookie.org/news/20060306-apps-secadv.html"},{"name":"24520","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24520"},{"name":"17221","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17221"},{"name":"VU#314540","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/314540"},{"name":"19348","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19348"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-06T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-04-04T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://pubcookie.org/news/20060306-apps-secadv.html"},{"name":"24520","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24520"},{"name":"17221","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17221"},{"name":"VU#314540","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/314540"},{"name":"19348","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19348"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1394","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://pubcookie.org/news/20060306-apps-secadv.html","refsource":"CONFIRM","url":"http://pubcookie.org/news/20060306-apps-secadv.html"},{"name":"24520","refsource":"OSVDB","url":"http://www.osvdb.org/24520"},{"name":"17221","refsource":"BID","url":"http://www.securityfocus.com/bid/17221"},{"name":"VU#314540","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/314540"},{"name":"19348","refsource":"SECUNIA","url":"http://secunia.com/advisories/19348"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1394","datePublished":"2006-03-26T23:00:00.000Z","dateReserved":"2006-03-26T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:20.922Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-26 23:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.0.0:*:*:*:*:*:*:*","matchCriteriaId":"32433F8A-8ECA-43E7-B73A-4AE115D3C6CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.1.0:*:*:*:*:*:*:*","matchCriteriaId":"8B5B4A6F-3CF2-43D0-8E32-79017E1DDB8F"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.1.1:*:*:*:*:*:*:*","matchCriteriaId":"C20FF0B0-61B9-4D61-9FA1-013D0867F7BB"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.2.0:*:*:*:*:*:*:*","matchCriteriaId":"7C7C9244-4AEA-4C70-BF96-9D8CD125339F"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.2.1:*:*:*:*:*:*:*","matchCriteriaId":"A2AFBDFF-11FB-4EE9-BCD2-9281AE33DE0C"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.2.1a:*:*:*:*:*:*:*","matchCriteriaId":"B8AF8CDA-1EF6-4B7B-8D75-3F5F8CE78113"},{"vulnerable":true,"criteria":"cpe:2.3:a:university_of_washington:pubcookie:3.3.0:*:*:*:*:*:*:*","matchCriteriaId":"6318AC28-703C-4154-9485-861B9E930310"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1394","Ordinal":"1","Title":"CVE-2006-1394","CVE":"CVE-2006-1394","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1394","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in the Microsoft IIS ISAPI filter (aka application server module) in University of Washington Pubcookie 3.1.0, 3.1.1, 3.2 before 3.2.1b, and 3.3 before 3.3.0a allow remote attackers to inject arbitrary web script or HTML via unspecified attack vectors.","Type":"Description","Title":"CVE-2006-1394"},{"CveYear":"2006","CveId":"1394","Ordinal":"2","NoteData":"2006-03-26","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1394","Ordinal":"3","NoteData":"2006-04-04","Type":"Other","Title":"Modified"}]}}}