{"api_version":"1","generated_at":"2026-07-24T22:01:35+00:00","cve":"CVE-2006-1717","urls":{"html":"https://cve.report/CVE-2006-1717","api":"https://cve.report/api/cve/CVE-2006-1717.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1717","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1717"},"summary":{"title":"CVE-2006-1717","description":"Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-11 23:02:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.1","severity":"","vector":"AV:N/AC:H/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/advisories/19516","name":"http://secunia.com/advisories/19516","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"MyBB Cross-Site Scripting and Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/430464/100/0/threaded","name":"http://www.securityfocus.com/archive/1/430464/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17427","name":"http://www.securityfocus.com/bid/17427","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"MyBulletinBoard Newthread.PHP HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25730","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25730","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1717","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1717","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1717","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mybulletinboard","cpe5":"mybulletinboard","cpe6":"1.10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1717","cve":"CVE-2006-1717","epss":"0.013020000","percentile":"0.674900000","score_date":"2026-07-23","updated_at":"2026-07-24 00:10:14"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:19:49.484Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19516","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19516"},{"name":"17427","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17427"},{"name":"20060409 MyBB 1.10 'newthread.php' < CrossSiteScripting >","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/430464/100/0/threaded"},{"name":"mybb-newthread-xss(25730)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25730"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-09T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19516","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19516"},{"name":"17427","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17427"},{"name":"20060409 MyBB 1.10 'newthread.php' < CrossSiteScripting >","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/430464/100/0/threaded"},{"name":"mybb-newthread-xss(25730)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25730"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1717","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19516","refsource":"SECUNIA","url":"http://secunia.com/advisories/19516"},{"name":"17427","refsource":"BID","url":"http://www.securityfocus.com/bid/17427"},{"name":"20060409 MyBB 1.10 'newthread.php' < CrossSiteScripting >","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/430464/100/0/threaded"},{"name":"mybb-newthread-xss(25730)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25730"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1717","datePublished":"2006-04-11T23:00:00.000Z","dateReserved":"2006-04-11T00:00:00.000Z","dateUpdated":"2024-08-07T17:19:49.484Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-11 23:02:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","baseScore":5.1,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mybulletinboard:mybulletinboard:1.10:*:*:*:*:*:*:*","matchCriteriaId":"0846A9BC-9FFC-4C93-911D-431688A6FB58"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1717","Ordinal":"1","Title":"CVE-2006-1717","CVE":"CVE-2006-1717","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1717","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in newthread.php in MyBB (aka MyBulletinBoard) 1.10, when configured to permit new threads by unregistered users, allows remote attackers to inject arbitrary web script or HTML via the username.","Type":"Description","Title":"CVE-2006-1717"},{"CveYear":"2006","CveId":"1717","Ordinal":"2","NoteData":"2006-04-11","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1717","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}