{"api_version":"1","generated_at":"2026-05-14T12:27:22+00:00","cve":"CVE-2006-1841","urls":{"html":"https://cve.report/CVE-2006-1841","api":"https://cve.report/api/cve/CVE-2006-1841.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1841","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1841"},"summary":{"title":"CVE-2006-1841","description":"Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-19 16:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"2.6","severity":"","vector":"AV:N/AC:H/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.vupen.com/english/advisories/2006/1375","name":"http://www.vupen.com/english/advisories/2006/1375","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25914","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25914","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/431120/100/0/threaded","name":"http://www.securityfocus.com/archive/1/431120/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17550","name":"http://www.securityfocus.com/bid/17550","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BoastMachine Search.PHP Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/19711","name":"http://secunia.com/advisories/19711","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Secunia - Advisories - bMachine Search Feature Cross-Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1841","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1841","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1841","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kailash_nadh","cpe5":"boastmachine","cpe6":"2.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1841","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kailash_nadh","cpe5":"boastmachine","cpe6":"2.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1841","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kailash_nadh","cpe5":"boastmachine","cpe6":"2.8","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"1841","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"kailash_nadh","cpe5":"boastmachine","cpe6":"2.9b","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1841","cve":"CVE-2006-1841","epss":"0.004270000","percentile":"0.624100000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:27:29.463Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"19711","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19711"},{"name":"20060416 Xss In bMachine 2&#1643;7","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431120/100/0/threaded"},{"name":"ADV-2006-1375","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1375"},{"name":"boastmachine-search-xss(25914)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25914"},{"name":"17550","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17550"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-16T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"19711","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19711"},{"name":"20060416 Xss In bMachine 2&#1643;7","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431120/100/0/threaded"},{"name":"ADV-2006-1375","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1375"},{"name":"boastmachine-search-xss(25914)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25914"},{"name":"17550","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17550"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1841","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"19711","refsource":"SECUNIA","url":"http://secunia.com/advisories/19711"},{"name":"20060416 Xss In bMachine 2&#1643;7","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431120/100/0/threaded"},{"name":"ADV-2006-1375","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1375"},{"name":"boastmachine-search-xss(25914)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25914"},{"name":"17550","refsource":"BID","url":"http://www.securityfocus.com/bid/17550"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1841","datePublished":"2006-04-19T16:00:00.000Z","dateReserved":"2006-04-19T00:00:00.000Z","dateUpdated":"2024-08-07T17:27:29.463Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-19 16:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","baseScore":2.6,"accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:kailash_nadh:boastmachine:2.5:*:*:*:*:*:*:*","matchCriteriaId":"B19759CD-3F3D-4A96-8DD0-828BA628427D"},{"vulnerable":true,"criteria":"cpe:2.3:a:kailash_nadh:boastmachine:2.7:*:*:*:*:*:*:*","matchCriteriaId":"6FD75997-6BFC-4161-A12A-8AB03FBDB562"},{"vulnerable":true,"criteria":"cpe:2.3:a:kailash_nadh:boastmachine:2.8:*:*:*:*:*:*:*","matchCriteriaId":"3AC1D5AE-1D9C-416A-8A34-61931C810478"},{"vulnerable":true,"criteria":"cpe:2.3:a:kailash_nadh:boastmachine:2.9b:*:*:*:*:*:*:*","matchCriteriaId":"73D3FA6A-5221-4607-961F-075A78EC6BEA"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1841","Ordinal":"1","Title":"CVE-2006-1841","CVE":"CVE-2006-1841","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1841","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in search.php in boastMachine (bMachine) 2.7, and possibly other versions before 2.9b, allows remote attackers to inject arbitrary web script or HTML via the key parameter, as used by the search field.","Type":"Description","Title":"CVE-2006-1841"},{"CveYear":"2006","CveId":"1841","Ordinal":"2","NoteData":"2006-04-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1841","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}