{"api_version":"1","generated_at":"2026-07-23T13:26:48+00:00","cve":"CVE-2006-2975","urls":{"html":"https://cve.report/CVE-2006-2975","api":"https://cve.report/api/cve/CVE-2006-2975.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-2975","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-2975"},"summary":{"title":"CVE-2006-2975","description":"Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG.  NOTE: portions of this description's details are obtained from third party information.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-12 22:02:00","updated_at":"2018-10-18 16:45:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/2221","name":"ADV-2006-2221","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27006","name":"pblguestbook-multiple-xss(27006)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/436408/100/0/threaded","name":"20060607 PBL Guestbook v1.31 - XSS","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20526","name":"20526","refsource":"SECUNIA","tags":[],"title":"PBL Guestbook Script Insertion and SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1088","name":"1088","refsource":"SREASON","tags":[],"title":"SecurityReason - PBL Guestbook v1.31 - XSS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-2975","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-2975","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"2975","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pbl_guestbook","cpe5":"pbl_guestbook","cpe6":"1.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"2975","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pbl_guestbook","cpe5":"pbl_guestbook","cpe6":"1.31","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-2975","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG.  NOTE: portions of this description's details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"20526","refsource":"SECUNIA","url":"http://secunia.com/advisories/20526"},{"name":"ADV-2006-2221","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2221"},{"name":"pblguestbook-multiple-xss(27006)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27006"},{"name":"20060607 PBL Guestbook v1.31 - XSS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/436408/100/0/threaded"},{"name":"1088","refsource":"SREASON","url":"http://securityreason.com/securityalert/1088"}]}},"nvd":{"publishedDate":"2006-06-12 22:02:00","lastModifiedDate":"2018-10-18 16:45:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":2.6},"severity":"LOW","exploitabilityScore":4.9,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pbl_guestbook:pbl_guestbook:1.31:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"2975","Ordinal":"18295","Title":"CVE-2006-2975","CVE":"CVE-2006-2975","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"2975","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in pblguestbook.php in PBL Guestbook 1.31 allow remote attackers to inject arbitrary web script or HTML via javascript in the SRC attribute of IMG tags in the (1) name, (2) email, and (3) website parameter, which bypasses XSS protection mechanisms that check for SCRIPT tags but not IMG.  NOTE: portions of this description's details are obtained from third party information.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"2975","Ordinal":"2","NoteData":"2006-06-12","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"2975","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}