{"api_version":"1","generated_at":"2026-06-20T18:59:14+00:00","cve":"CVE-2006-2616","urls":{"html":"https://cve.report/CVE-2006-2616","api":"https://cve.report/api/cve/CVE-2006-2616.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2616","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2616"},"summary":{"title":"CVE-2006-2616","description":"SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-05-26 01:06:00","updated_at":"2018-10-18 16:40:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26658","name":"hs-webhostdirectory-search-sql-injection(26658)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20276","name":"20276","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"AlstraSoft Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/434912/100/0/threaded","name":"20060523 AlstraSoft Web Host Directory v1.2","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1973","name":"ADV-2006-1973","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1972","name":"ADV-2006-1972","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/955","name":"955","refsource":"SREASON","tags":[],"title":"AlstraSoft Web Host Directory v1.2 - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20278","name":"20278","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"HyperStop Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26653","name":"webhostdirectory-search-sql-injection(26653)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2616","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2616","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2616","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alstrasoft","cpe5":"webhost_directory","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2616","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alstrasoft","cpe5":"webhost_directory","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2616","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"webhostdirectory-search-sql-injection(26653)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26653"},{"name":"955","refsource":"SREASON","url":"http://securityreason.com/securityalert/955"},{"name":"hs-webhostdirectory-search-sql-injection(26658)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26658"},{"name":"ADV-2006-1972","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1972"},{"name":"20060523 AlstraSoft Web Host Directory v1.2","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/434912/100/0/threaded"},{"name":"20276","refsource":"SECUNIA","url":"http://secunia.com/advisories/20276"},{"name":"20278","refsource":"SECUNIA","url":"http://secunia.com/advisories/20278"},{"name":"ADV-2006-1973","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1973"}]}},"nvd":{"publishedDate":"2006-05-26 01:06:00","lastModifiedDate":"2018-10-18 16:40:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alstrasoft:webhost_directory:1.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2616","Ordinal":"17935","Title":"CVE-2006-2616","CVE":"CVE-2006-2616","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2616","Ordinal":"1","NoteData":"SQL injection vulnerability in the search script in (1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to execute arbitrary SQL commands via the uri parameter.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2616","Ordinal":"2","NoteData":"2006-05-25","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2616","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}