{"api_version":"1","generated_at":"2026-07-23T09:00:49+00:00","cve":"CVE-2006-1580","urls":{"html":"https://cve.report/CVE-2006-1580","api":"https://cve.report/api/cve/CVE-2006-1580.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1580","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1580"},"summary":{"title":"CVE-2006-1580","description":"Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-02 21:04:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/24328","name":"http://www.osvdb.org/24328","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/17351","name":"http://www.securityfocus.com/bid/17351","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugzero Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/19492","name":"http://secunia.com/advisories/19492","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Bugzero Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25601","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25601","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html","name":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: Bugzero XSS vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1195","name":"http://www.vupen.com/english/advisories/2006/1195","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24329","name":"http://www.osvdb.org/24329","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1580","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1580","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1580","vulnerable":"1","versionEndIncluding":"4.3.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"websina","cpe5":"bugzero","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1580","cve":"CVE-2006-1580","epss":"0.019970000","percentile":"0.836700000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:48.487Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"17351","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17351"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html"},{"name":"bugzero-query-edit-xss(25601)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25601"},{"name":"ADV-2006-1195","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1195"},{"name":"19492","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19492"},{"name":"24328","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24328"},{"name":"24329","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24329"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"17351","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17351"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html"},{"name":"bugzero-query-edit-xss(25601)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25601"},{"name":"ADV-2006-1195","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1195"},{"name":"19492","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19492"},{"name":"24328","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24328"},{"name":"24329","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24329"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1580","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"17351","refsource":"BID","url":"http://www.securityfocus.com/bid/17351"},{"name":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html"},{"name":"bugzero-query-edit-xss(25601)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25601"},{"name":"ADV-2006-1195","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1195"},{"name":"19492","refsource":"SECUNIA","url":"http://secunia.com/advisories/19492"},{"name":"24328","refsource":"OSVDB","url":"http://www.osvdb.org/24328"},{"name":"24329","refsource":"OSVDB","url":"http://www.osvdb.org/24329"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1580","datePublished":"2006-04-02T21:00:00.000Z","dateReserved":"2006-04-02T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:48.487Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-02 21:04:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:websina:bugzero:*:*:*:*:*:*:*:*","versionEndIncluding":"4.3.1","matchCriteriaId":"E8E3A26D-EE7E-4CD3-92AF-564D329D6DCC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1580","Ordinal":"1","Title":"CVE-2006-1580","CVE":"CVE-2006-1580","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1580","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.","Type":"Description","Title":"CVE-2006-1580"},{"CveYear":"2006","CveId":"1580","Ordinal":"2","NoteData":"2006-04-02","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1580","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}