{"api_version":"1","generated_at":"2026-07-23T08:53:20+00:00","cve":"CVE-2006-2167","urls":{"html":"https://cve.report/CVE-2006-2167","api":"https://cve.report/api/cve/CVE-2006-2167.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2167","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2167"},"summary":{"title":"CVE-2006-2167","description":"Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-05-04 12:38:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26215","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26215","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/432727/100/0/threaded","name":"http://www.securityfocus.com/archive/1/432727/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1637","name":"http://www.vupen.com/english/advisories/2006/1637","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/831","name":"http://securityreason.com/securityalert/831","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityReason - SF-Users V1.0 XSS injection","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/19932","name":"http://secunia.com/advisories/19932","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"SF-Users \"register.php\" Script Insertion Vulnerability - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/17783","name":"http://www.securityfocus.com/bid/17783","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SF-Users Username HTML Injection Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2167","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2167","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2167","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"sloughflash","cpe5":"sf-users","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"2167","cve":"CVE-2006-2167","epss":"0.005270000","percentile":"0.671440000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:43:28.319Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"sfusers-register-xss(26215)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26215"},{"name":"17783","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17783"},{"name":"831","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/831"},{"name":"19932","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19932"},{"name":"ADV-2006-1637","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1637"},{"name":"20060502 SF-Users V1.0 XSS injection","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/432727/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-05-02T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-18T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"sfusers-register-xss(26215)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26215"},{"name":"17783","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17783"},{"name":"831","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/831"},{"name":"19932","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19932"},{"name":"ADV-2006-1637","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1637"},{"name":"20060502 SF-Users V1.0 XSS injection","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/432727/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2167","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"sfusers-register-xss(26215)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26215"},{"name":"17783","refsource":"BID","url":"http://www.securityfocus.com/bid/17783"},{"name":"831","refsource":"SREASON","url":"http://securityreason.com/securityalert/831"},{"name":"19932","refsource":"SECUNIA","url":"http://secunia.com/advisories/19932"},{"name":"ADV-2006-1637","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1637"},{"name":"20060502 SF-Users V1.0 XSS injection","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/432727/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-2167","datePublished":"2006-05-04T10:00:00.000Z","dateReserved":"2006-05-03T00:00:00.000Z","dateUpdated":"2024-08-07T17:43:28.319Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-05-04 12:38:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:sloughflash:sf-users:1.0:*:*:*:*:*:*:*","matchCriteriaId":"F7713A55-5BB6-4BD6-BFE8-80BADB7CA08F"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2167","Ordinal":"1","Title":"CVE-2006-2167","CVE":"CVE-2006-2167","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2167","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.","Type":"Description","Title":"CVE-2006-2167"},{"CveYear":"2006","CveId":"2167","Ordinal":"2","NoteData":"2006-05-04","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2167","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}