{"api_version":"1","generated_at":"2026-06-20T18:59:12+00:00","cve":"CVE-2006-2617","urls":{"html":"https://cve.report/CVE-2006-2617","api":"https://cve.report/api/cve/CVE-2006-2617.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2617","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2617"},"summary":{"title":"CVE-2006-2617","description":"(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error.  NOTE: this issue might be resultant from SQL injection.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-05-26 01:06:00","updated_at":"2018-10-18 16:40:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26661","name":"hs-webhostdirectory-multiple-path-disclosure(26661)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26656","name":"webhostdirectory-multiple-path-disclosure(26656)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20276","name":"20276","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"AlstraSoft Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/434912/100/0/threaded","name":"20060523 AlstraSoft Web Host Directory v1.2","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1973","name":"ADV-2006-1973","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/1972","name":"ADV-2006-1972","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/955","name":"955","refsource":"SREASON","tags":[],"title":"AlstraSoft Web Host Directory v1.2 - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20278","name":"20278","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"HyperStop Web Host Directory SQL Injection and Script Insertion - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.sitepoint.com/forums/showthread.php?t=311969","name":"http://www.sitepoint.com/forums/showthread.php?t=311969","refsource":"MISC","tags":[],"title":"The SitePoint Forums","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2617","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2617","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2617","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alstrasoft","cpe5":"webhost_directory","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2617","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"alstrasoft","cpe5":"webhost_directory","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2617","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error.  NOTE: this issue might be resultant from SQL injection."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"hs-webhostdirectory-multiple-path-disclosure(26661)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26661"},{"name":"webhostdirectory-multiple-path-disclosure(26656)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26656"},{"name":"955","refsource":"SREASON","url":"http://securityreason.com/securityalert/955"},{"name":"http://www.sitepoint.com/forums/showthread.php?t=311969","refsource":"MISC","url":"http://www.sitepoint.com/forums/showthread.php?t=311969"},{"name":"ADV-2006-1972","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1972"},{"name":"20060523 AlstraSoft Web Host Directory v1.2","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/434912/100/0/threaded"},{"name":"20276","refsource":"SECUNIA","url":"http://secunia.com/advisories/20276"},{"name":"20278","refsource":"SECUNIA","url":"http://secunia.com/advisories/20278"},{"name":"ADV-2006-1973","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1973"}]}},"nvd":{"publishedDate":"2006-05-26 01:06:00","lastModifiedDate":"2018-10-18 16:40:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE","baseScore":5},"severity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:alstrasoft:webhost_directory:1.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2617","Ordinal":"17936","Title":"CVE-2006-2617","CVE":"CVE-2006-2617","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2617","Ordinal":"1","NoteData":"(1) AlstraSoft Web Host Directory 1.2, aka (2) HyperStop WebHost Directory 1.2, allows remote attackers to obtain the installation path via an invalid entry in the Username field on the login page, which causes the path to be displayed in an SQL error.  NOTE: this issue might be resultant from SQL injection.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2617","Ordinal":"2","NoteData":"2006-05-25","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2617","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}