{"api_version":"1","generated_at":"2026-07-23T08:15:19+00:00","cve":"CVE-2006-3049","urls":{"html":"https://cve.report/CVE-2006-3049","api":"https://cve.report/api/cve/CVE-2006-3049.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3049","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3049"},"summary":{"title":"CVE-2006-3049","description":"Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (3) address2, (4) county, (5) postcode, (6) email, (7) phone, or (8) mobile parameters to booking2.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-16 10:02:00","updated_at":"2017-07-20 01:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.attrition.org/pipermail/vim/2006-June/000868.html","name":"20060615 [SECUNIA] Re: 20612 typo? (fwd)","refsource":"VIM","tags":[],"title":"[VIM] [SECUNIA] Re: 20612 typo? (fwd)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27150","name":"ticket-booking-booking2-xss(27150)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/bugtraq/2006-06/0111.html","name":"20060609 mole.com.ua Ticket Booking Script - XSS","refsource":"BUGTRAQ","tags":[],"title":"NEOHAPSIS - Peace of Mind Through Integrity and Insight","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://secunia.com/advisories/20612","name":"20612","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"Secunia - Advisories - Mole Group Ticket Booking Script Cross-Site Scripting","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2305","name":"ADV-2006-2305","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3049","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3049","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3049","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mole_group_ticket_booking_script","cpe5":"mole_group_ticket_booking_script","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3049","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mole_group_ticket_booking_script","cpe5":"mole_group_ticket_booking_script","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3049","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (3) address2, (4) county, (5) postcode, (6) email, (7) phone, or (8) mobile parameters to booking2.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"refsource":"VIM","name":"20060615 [SECUNIA] Re: 20612 typo? (fwd)","url":"http://www.attrition.org/pipermail/vim/2006-June/000868.html"},{"name":"ticket-booking-booking2-xss(27150)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27150"},{"name":"20612","refsource":"SECUNIA","url":"http://secunia.com/advisories/20612"},{"name":"ADV-2006-2305","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2305"},{"name":"20060609 mole.com.ua Ticket Booking Script - XSS","refsource":"BUGTRAQ","url":"http://archives.neohapsis.com/archives/bugtraq/2006-06/0111.html"}]}},"nvd":{"publishedDate":"2006-06-16 10:02:00","lastModifiedDate":"2017-07-20 01:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:mole_group_ticket_booking_script:mole_group_ticket_booking_script:*:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3049","Ordinal":"18374","Title":"CVE-2006-3049","CVE":"CVE-2006-3049","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3049","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in booking3.php in Mole Group Ticket Booking Script allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) address1, (3) address2, (4) county, (5) postcode, (6) email, (7) phone, or (8) mobile parameters to booking2.php.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3049","Ordinal":"2","NoteData":"2006-06-16","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3049","Ordinal":"3","NoteData":"2017-07-19","Type":"Other","Title":"Modified"}]}}}