{"api_version":"1","generated_at":"2026-07-23T11:11:40+00:00","cve":"CVE-2006-1410","urls":{"html":"https://cve.report/CVE-2006-1410","api":"https://cve.report/api/cve/CVE-2006-1410.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1410","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1410"},"summary":{"title":"CVE-2006-1410","description":"Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-28 11:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/1099","name":"http://www.vupen.com/english/advisories/2006/1099","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25434","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25434","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17258","name":"http://www.securityfocus.com/bid/17258","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Xigla Absolute Live Support XE Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/19415","name":"http://secunia.com/advisories/19415","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Absolute Live Support XE Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24131","name":"http://www.osvdb.org/24131","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html","name":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Absolute Live Support XE V2.0 XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1410","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1410","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1410","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"xigla","cpe5":"absolute_live_support_xe","cpe6":"2.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1410","cve":"CVE-2006-1410","epss":"0.005270000","percentile":"0.671490000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:21.439Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"absolutelivesupport-register-xss(25434)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25434"},{"name":"24131","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24131"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html"},{"name":"17258","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17258"},{"name":"19415","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19415"},{"name":"ADV-2006-1099","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1099"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-25T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"absolutelivesupport-register-xss(25434)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25434"},{"name":"24131","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24131"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html"},{"name":"17258","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17258"},{"name":"19415","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19415"},{"name":"ADV-2006-1099","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1099"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1410","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"absolutelivesupport-register-xss(25434)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25434"},{"name":"24131","refsource":"OSVDB","url":"http://www.osvdb.org/24131"},{"name":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/03/absolute-live-support-xe-v20-xss-vuln.html"},{"name":"17258","refsource":"BID","url":"http://www.securityfocus.com/bid/17258"},{"name":"19415","refsource":"SECUNIA","url":"http://secunia.com/advisories/19415"},{"name":"ADV-2006-1099","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1099"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1410","datePublished":"2006-03-28T11:00:00.000Z","dateReserved":"2006-03-28T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:21.439Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-28 11:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:xigla:absolute_live_support_xe:2.0:*:*:*:*:*:*:*","matchCriteriaId":"2BFA264F-E8F6-4BF2-996A-ADC2F4D0DFD2"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1410","Ordinal":"1","Title":"CVE-2006-1410","CVE":"CVE-2006-1410","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1410","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in XIGLA Absolute Live Support XE 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Screen name or (2) Session Topic field.","Type":"Description","Title":"CVE-2006-1410"},{"CveYear":"2006","CveId":"1410","Ordinal":"2","NoteData":"2006-03-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1410","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}