{"api_version":"1","generated_at":"2026-07-23T08:17:38+00:00","cve":"CVE-2006-3312","urls":{"html":"https://cve.report/CVE-2006-3312","api":"https://cve.report/api/cve/CVE-2006-3312.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3312","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3312"},"summary":{"title":"CVE-2006-3312","description":"Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables.  NOTE: the vendor notified CVE via e-mail that this issue has been fixed in the 6.8 RC release.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-06-29 19:05:00","updated_at":"2018-10-18 16:46:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.osvdb.org/27614","name":"27614","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27355","name":"qatraq-multiple-xss(27355)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27607","name":"27607","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27613","name":"27613","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27600","name":"27600","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27609","name":"27609","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securityreason.com/securityalert/1169","name":"1169","refsource":"SREASON","tags":[],"title":"SecurityReason - QaTraq 6.5 RC: Multiple XSS Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27599","name":"27599","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27616","name":"27616","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27605","name":"27605","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27611","name":"27611","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27602","name":"27602","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://securitytracker.com/id?1016381","name":"1016381","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - QaTraq Input Validation Hole Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.attrition.org/pipermail/vim/2006-August/000969.html","name":"20060811 QaTraq multiple cross-site scripting vulnerabilities (fwd)","refsource":"VIM","tags":[],"title":"[VIM] QaTraq multiple cross-site scripting vulnerabilities (fwd)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27608","name":"27608","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27612","name":"27612","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/438151/100/0/threaded","name":"20060623 QaTraq 6.5 RC: Multiple XSS Vulnerabilities","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/27601","name":"27601","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27615","name":"27615","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27606","name":"27606","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27610","name":"27610","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.testmanagement.com/","name":"http://www.testmanagement.com/","refsource":"CONFIRM","tags":[],"title":"Software test case management","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://seclab.tuwien.ac.at/advisories/TUVSA-0606-001.txt","name":"http://seclab.tuwien.ac.at/advisories/TUVSA-0606-001.txt","refsource":"MISC","tags":["Exploit"],"title":"","mime":"text/plain","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.osvdb.org/27603","name":"27603","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.osvdb.org/27604","name":"27604","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/bid/18620","name":"18620","refsource":"BID","tags":[],"title":"QaTraq Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3312","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3312","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3312","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qatraq","cpe5":"qatraq","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3312","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"qatraq","cpe5":"qatraq","cpe6":"6.5","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3312","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables.  NOTE: the vendor notified CVE via e-mail that this issue has been fixed in the 6.8 RC release."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"27603","refsource":"OSVDB","url":"http://www.osvdb.org/27603"},{"name":"20060811 QaTraq multiple cross-site scripting vulnerabilities (fwd)","refsource":"VIM","url":"http://www.attrition.org/pipermail/vim/2006-August/000969.html"},{"name":"http://www.testmanagement.com/","refsource":"CONFIRM","url":"http://www.testmanagement.com/"},{"name":"27611","refsource":"OSVDB","url":"http://www.osvdb.org/27611"},{"name":"27614","refsource":"OSVDB","url":"http://www.osvdb.org/27614"},{"name":"http://seclab.tuwien.ac.at/advisories/TUVSA-0606-001.txt","refsource":"MISC","url":"http://seclab.tuwien.ac.at/advisories/TUVSA-0606-001.txt"},{"name":"27602","refsource":"OSVDB","url":"http://www.osvdb.org/27602"},{"name":"27610","refsource":"OSVDB","url":"http://www.osvdb.org/27610"},{"name":"1016381","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016381"},{"name":"27612","refsource":"OSVDB","url":"http://www.osvdb.org/27612"},{"name":"27607","refsource":"OSVDB","url":"http://www.osvdb.org/27607"},{"name":"27606","refsource":"OSVDB","url":"http://www.osvdb.org/27606"},{"name":"18620","refsource":"BID","url":"http://www.securityfocus.com/bid/18620"},{"name":"27609","refsource":"OSVDB","url":"http://www.osvdb.org/27609"},{"name":"27608","refsource":"OSVDB","url":"http://www.osvdb.org/27608"},{"name":"27599","refsource":"OSVDB","url":"http://www.osvdb.org/27599"},{"name":"27613","refsource":"OSVDB","url":"http://www.osvdb.org/27613"},{"name":"27615","refsource":"OSVDB","url":"http://www.osvdb.org/27615"},{"name":"27605","refsource":"OSVDB","url":"http://www.osvdb.org/27605"},{"name":"1169","refsource":"SREASON","url":"http://securityreason.com/securityalert/1169"},{"name":"27616","refsource":"OSVDB","url":"http://www.osvdb.org/27616"},{"name":"qatraq-multiple-xss(27355)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27355"},{"name":"27600","refsource":"OSVDB","url":"http://www.osvdb.org/27600"},{"name":"27601","refsource":"OSVDB","url":"http://www.osvdb.org/27601"},{"name":"27604","refsource":"OSVDB","url":"http://www.osvdb.org/27604"},{"name":"20060623 QaTraq 6.5 RC: Multiple XSS Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/438151/100/0/threaded"}]}},"nvd":{"publishedDate":"2006-06-29 19:05:00","lastModifiedDate":"2018-10-18 16:46:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:qatraq:qatraq:6.5:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3312","Ordinal":"18637","Title":"CVE-2006-3312","CVE":"CVE-2006-3312","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3312","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in ashmans and Bill Echlin QaTraq 6.5 RC and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) link_print, (2) link_upgrade, (3) link_sql, (4) link_next, (5) link_prev, and (6) link_list parameters in top.inc as included by queries_view_search.php; the (7) msg, (8) component_name, and (9) component_desc parameters in (a) components_copy_content.php, (b) components_modify_content.php, and (c) components_new_content.php; the (10) title, (11) version, and (12) content parameters in design_copy_content.php; the (13) plan_title and (14) plan_content parameters in design_copy_plan_search.php; the (15) title, (16) minor_version, (17) new_version, and (18) content parameters in design_modify_content.php; the (19) title, (20) version, and (21) content parameters in design_new_content.php; the (22) plan_name and (23) plan_desc parameters in design_new_search.php; the (24) file_name parameter in download.php; the (25) username and (26) password parameters in login.php; the (27) title, (28) version, and (29) content parameters in phase_copy_content.php; the (30) content parameter in phase_delete_search.php; the (31) title, (32) minor_version, (33) new_version, and (34) content parameters in phase_modify_content.php; the (35) content, (36) title, (37) version, and (38) content parameters in phase_modify_search.php; the (39) content parameter in phase_view_search.php; the (40) msg, (41) product_name, and (42) product_desc parameters in products_copy_content.php; and possibly the (43) product_name and (44) product_desc parameters in (d) products_copy_search.php, and a large number of additional parameters and executables.  NOTE: the vendor notified CVE via e-mail that this issue has been fixed in the 6.8 RC release.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3312","Ordinal":"2","NoteData":"2006-06-29","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3312","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}