{"api_version":"1","generated_at":"2026-07-23T10:57:37+00:00","cve":"CVE-2006-1853","urls":{"html":"https://cve.report/CVE-2006-1853","api":"https://cve.report/api/cve/CVE-2006-1853.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-1853","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-1853"},"summary":{"title":"CVE-2006-1853","description":"Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-04-19 16:06:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.5","severity":"","vector":"AV:N/AC:L/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25926","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25926","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1415","name":"http://www.vupen.com/english/advisories/2006/1415","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html","name":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: ModernBill multiple SQL inj. vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17596","name":"http://www.securityfocus.com/bid/17596","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ModernGigabyte ModernBill User.PHP SQL Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/19641","name":"http://secunia.com/advisories/19641","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Secunia - Advisories - ModernBill Multiple SQL Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-1853","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-1853","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"1853","vulnerable":"1","versionEndIncluding":"4.3.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"moderngigabyte","cpe5":"modernbill","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"1853","cve":"CVE-2006-1853","epss":"0.004750000","percentile":"0.648390000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:27:29.222Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"modernbill-user-sql-injection(25926)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25926"},{"name":"17596","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17596"},{"name":"ADV-2006-1415","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1415"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html"},{"name":"19641","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19641"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-18T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"modernbill-user-sql-injection(25926)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25926"},{"name":"17596","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17596"},{"name":"ADV-2006-1415","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1415"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html"},{"name":"19641","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19641"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1853","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"modernbill-user-sql-injection(25926)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/25926"},{"name":"17596","refsource":"BID","url":"http://www.securityfocus.com/bid/17596"},{"name":"ADV-2006-1415","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1415"},{"name":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/04/modernbill-multiple-sql-inj-vuln.html"},{"name":"19641","refsource":"SECUNIA","url":"http://secunia.com/advisories/19641"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1853","datePublished":"2006-04-19T16:00:00.000Z","dateReserved":"2006-04-19T00:00:00.000Z","dateUpdated":"2024-08-07T17:27:29.222Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-04-19 16:06:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:P/A:P","baseScore":6.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:moderngigabyte:modernbill:*:*:*:*:*:*:*:*","versionEndIncluding":"4.3.2","matchCriteriaId":"A3C184BD-9FC2-494B-917F-6877C05E716E"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"1853","Ordinal":"1","Title":"CVE-2006-1853","CVE":"CVE-2006-1853","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"1853","Ordinal":"1","NoteData":"Multiple SQL injection vulnerabilities in ModernBill 4.3.2 and earlier allow remote attackers or administrators to execute arbitrary SQL commands via the (1) id parameter in (a) user.php, or (2) where and (3) order parameters to (b) admin.php.","Type":"Description","Title":"CVE-2006-1853"},{"CveYear":"2006","CveId":"1853","Ordinal":"2","NoteData":"2006-04-19","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"1853","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}