{"api_version":"1","generated_at":"2026-07-23T07:31:59+00:00","cve":"CVE-2006-2178","urls":{"html":"https://cve.report/CVE-2006-2178","api":"https://cve.report/api/cve/CVE-2006-2178.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2178","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2178"},"summary":{"title":"CVE-2006-2178","description":"Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp.  NOTE: vectors 1 and 2 might be resultant from SQL injection.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-05-04 12:38:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/25198","name":"http://www.osvdb.org/25198","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.vupen.com/english/advisories/2006/1630","name":"http://www.vupen.com/english/advisories/2006/1630","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26202","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26202","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html","name":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"- UNSECURED SYSTEMS -: CyberBuild vuln.","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/25197","name":"http://www.osvdb.org/25197","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/17829","name":"http://www.securityfocus.com/bid/17829","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"CyberBuild Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/19889","name":"http://secunia.com/advisories/19889","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"CyberBuild Multiple Vulnerabilities - Secunia Advisories - Vulnerability Intelligence - Secunia.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/25199","name":"http://www.osvdb.org/25199","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2178","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2178","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2178","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"smartwin_technology","cpe5":"cyberoffice_warehouse_builder","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":{"cve_year":"2006","cve_id":"2178","cve":"CVE-2006-2178","epss":"0.007200000","percentile":"0.725140000","score_date":"2026-04-20","updated_at":"2026-04-21 00:07:48"},"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T17:43:27.512Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-1630","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1630"},{"name":"25198","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/25198"},{"name":"25199","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/25199"},{"name":"25197","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/25197"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html"},{"name":"17829","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17829"},{"name":"cyberbuild-multiple-xss(26202)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26202"},{"name":"19889","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19889"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-05-01T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp.  NOTE: vectors 1 and 2 might be resultant from SQL injection."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-1630","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1630"},{"name":"25198","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/25198"},{"name":"25199","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/25199"},{"name":"25197","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/25197"},{"tags":["x_refsource_MISC"],"url":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html"},{"name":"17829","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17829"},{"name":"cyberbuild-multiple-xss(26202)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26202"},{"name":"19889","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19889"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2178","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp.  NOTE: vectors 1 and 2 might be resultant from SQL injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-1630","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1630"},{"name":"25198","refsource":"OSVDB","url":"http://www.osvdb.org/25198"},{"name":"25199","refsource":"OSVDB","url":"http://www.osvdb.org/25199"},{"name":"25197","refsource":"OSVDB","url":"http://www.osvdb.org/25197"},{"name":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html","refsource":"MISC","url":"http://pridels0.blogspot.com/2006/05/cyberbuild-vuln.html"},{"name":"17829","refsource":"BID","url":"http://www.securityfocus.com/bid/17829"},{"name":"cyberbuild-multiple-xss(26202)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26202"},{"name":"19889","refsource":"SECUNIA","url":"http://secunia.com/advisories/19889"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-2178","datePublished":"2006-05-04T10:00:00.000Z","dateReserved":"2006-05-03T00:00:00.000Z","dateUpdated":"2024-08-07T17:43:27.512Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-05-04 12:38:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:smartwin_technology:cyberoffice_warehouse_builder:*:*:*:*:*:*:*:*","matchCriteriaId":"4F8A8353-1CFE-42FB-B380-E37AEF76EE79"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2178","Ordinal":"1","Title":"CVE-2006-2178","CVE":"CVE-2006-2178","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2178","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in CyberBuild allow remote attackers to inject arbitrary web script or HTML via the (1) SessionID parameter to login.asp, (2) ProductIndex parameter to browse0.htm, (3) rowcolor parameter to result.asp, or (4) heading parameter to result.asp.  NOTE: vectors 1 and 2 might be resultant from SQL injection.","Type":"Description","Title":"CVE-2006-2178"},{"CveYear":"2006","CveId":"2178","Ordinal":"2","NoteData":"2006-05-04","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2178","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}