{"api_version":"1","generated_at":"2026-07-23T14:51:59+00:00","cve":"CVE-2006-1486","urls":{"html":"https://cve.report/CVE-2006-1486","api":"https://cve.report/api/cve/CVE-2006-1486.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1486","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1486"},"summary":{"title":"CVE-2006-1486","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-03-29 02:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/1128","name":"http://www.vupen.com/english/advisories/2006/1128","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24186","name":"http://www.osvdb.org/24186","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/19429","name":"http://secunia.com/advisories/19429","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"realestateZONE Cross-Site Scripting Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17277","name":"http://www.securityfocus.com/bid/17277","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"RealestateZONE Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html","name":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: realestateZONE 4.2 Multiple XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25487","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25487","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1486","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1486","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1486","vulnerable":"1","versionEndIncluding":"4.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"fusionzone","cpe5":"realestatezone","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1486","cve":"CVE-2006-1486","epss":"0.022950000","percentile":"0.847460000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:12:22.075Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"24186","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24186"},{"name":"realestatezone-index-xss(25487)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25487"},{"name":"19429","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19429"},{"name":"ADV-2006-1128","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1128"},{"name":"17277","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17277"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-03-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"24186","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24186"},{"name":"realestatezone-index-xss(25487)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25487"},{"name":"19429","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19429"},{"name":"ADV-2006-1128","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1128"},{"name":"17277","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17277"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1486","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"24186","refsource":"OSVDB","url":"http://www.osvdb.org/24186"},{"name":"realestatezone-index-xss(25487)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25487"},{"name":"19429","refsource":"SECUNIA","url":"http://secunia.com/advisories/19429"},{"name":"ADV-2006-1128","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1128"},{"name":"17277","refsource":"BID","url":"http://www.securityfocus.com/bid/17277"},{"name":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/03/realestatezone-42-multiple-xss-vuln.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1486","datePublished":"2006-03-29T02:00:00.000Z","dateReserved":"2006-03-28T00:00:00.000Z","dateUpdated":"2024-08-07T17:12:22.075Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-03-29 02:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:fusionzone:realestatezone:*:*:*:*:*:*:*:*","versionEndIncluding":"4.2","matchCriteriaId":"B99FD2C0-12C5-455E-8CBC-C6B5CA25EB2B"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1486","Ordinal":"1","Title":"CVE-2006-1486","CVE":"CVE-2006-1486","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1486","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.cfm in realestateZONE 4.2 allow remote attackers to inject arbitrary web script or HTML via the (1) bamin, (2) bemin, (3) pmin, and (4) state parameters.","Type":"Description","Title":"CVE-2006-1486"},{"CveYear":"2006","CveId":"1486","Ordinal":"2","NoteData":"2006-03-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1486","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}