{"api_version":"1","generated_at":"2026-07-23T08:57:38+00:00","cve":"CVE-2006-1658","urls":{"html":"https://cve.report/CVE-2006-1658","api":"https://cve.report/api/cve/CVE-2006-1658.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1658","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1658"},"summary":{"title":"CVE-2006-1658","description":"Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-07 10:04:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://evuln.com/vulns/121/summary.html","name":"http://evuln.com/vulns/121/summary.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"eVuln.com -  N.T. Version 1.1.0 XSS and PHP Code Insertion  Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/24398","name":"http://www.osvdb.org/24398","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25639","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25639","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19526","name":"http://secunia.com/advisories/19526","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"N.T. Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17387","name":"http://www.securityfocus.com/bid/17387","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Chucky A. Ivey N.T. Index.PHP Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1243","name":"http://www.vupen.com/english/advisories/2006/1243","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/431344/100/0/threaded","name":"http://www.securityfocus.com/archive/1/431344/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1658","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1658","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1658","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"chucky_a._ivey","cpe5":"n.t.","cpe6":"1.1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1658","cve":"CVE-2006-1658","epss":"0.007250000","percentile":"0.726110000","score_date":"2026-04-19","updated_at":"2026-04-20 00:11:20"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:49.187Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://evuln.com/vulns/121/summary.html"},{"name":"ADV-2006-1243","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1243"},{"name":"24398","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/24398"},{"name":"20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431344/100/0/threaded"},{"name":"19526","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19526"},{"name":"nt-ticker-file-include(25639)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25639"},{"name":"17387","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17387"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-05T00:00:00.000Z","descriptions":[{"lang":"en","value":"Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://evuln.com/vulns/121/summary.html"},{"name":"ADV-2006-1243","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1243"},{"name":"24398","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/24398"},{"name":"20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431344/100/0/threaded"},{"name":"19526","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19526"},{"name":"nt-ticker-file-include(25639)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25639"},{"name":"17387","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17387"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1658","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://evuln.com/vulns/121/summary.html","refsource":"MISC","url":"http://evuln.com/vulns/121/summary.html"},{"name":"ADV-2006-1243","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1243"},{"name":"24398","refsource":"OSVDB","url":"http://www.osvdb.org/24398"},{"name":"20060419 [eVuln] N.T. Version 1.1.0 XSS and PHP Code Insertion Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431344/100/0/threaded"},{"name":"19526","refsource":"SECUNIA","url":"http://secunia.com/advisories/19526"},{"name":"nt-ticker-file-include(25639)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25639"},{"name":"17387","refsource":"BID","url":"http://www.securityfocus.com/bid/17387"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1658","datePublished":"2006-04-07T10:00:00.000Z","dateReserved":"2006-04-07T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:49.187Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-07 10:04:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:chucky_a._ivey:n.t.:1.1.0:*:*:*:*:*:*:*","matchCriteriaId":"D8C9BF07-AE0E-4F8A-8BE0-CEED1764E0CB"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1658","Ordinal":"1","Title":"CVE-2006-1658","CVE":"CVE-2006-1658","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1658","Ordinal":"1","NoteData":"Direct static code injection vulnerability in ticker.db.php in Chucky A. Ivey N.T.  1.1.0 allows remote administrators to insert arbitrary PHP code into the config file, which is included other N.T. scripts.","Type":"Description","Title":"CVE-2006-1658"},{"CveYear":"2006","CveId":"1658","Ordinal":"2","NoteData":"2006-04-07","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1658","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}