{"api_version":"1","generated_at":"2026-07-23T08:55:43+00:00","cve":"CVE-2006-3618","urls":{"html":"https://cve.report/CVE-2006-3618","api":"https://cve.report/api/cve/CVE-2006-3618.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3618","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3618"},"summary":{"title":"CVE-2006-3618","description":"SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-18 15:47:00","updated_at":"2018-10-18 16:48:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.securityfocus.com/archive/1/439486/100/0/threaded","name":"20060707 PBL Guestbook <= 1.32 XSS & SQL Querys Vulnerabilities","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27624","name":"pblguestbook-pblguestbook-sql-injection(27624)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.neosecurityteam.net/index.php?action=advisories&id=23","name":"http://www.neosecurityteam.net/index.php?action=advisories&id=23","refsource":"MISC","tags":["Exploit","Vendor Advisory"],"title":"neosecurityteam.net - neosecurityteam Resources and Information. This website is for sale!","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3618","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3618","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3618","vulnerable":"1","versionEndIncluding":"1.32","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"pixelated_by_lev","cpe5":"pixelated_by_lev_guestbook","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3618","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"pblguestbook-pblguestbook-sql-injection(27624)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27624"},{"name":"20060707 PBL Guestbook <= 1.32 XSS & SQL Querys Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/439486/100/0/threaded"},{"name":"http://www.neosecurityteam.net/index.php?action=advisories&id=23","refsource":"MISC","url":"http://www.neosecurityteam.net/index.php?action=advisories&id=23"}]}},"nvd":{"publishedDate":"2006-07-18 15:47:00","lastModifiedDate":"2018-10-18 16:48:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":7.5},"severity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:pixelated_by_lev:pixelated_by_lev_guestbook:*:*:*:*:*:*:*:*","versionEndIncluding":"1.32","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3618","Ordinal":"18944","Title":"CVE-2006-3618","CVE":"CVE-2006-3618","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3618","Ordinal":"1","NoteData":"SQL injection vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to execute arbitrary SQL commands via the (1) name, (2) email, (3) website, (4) comments, (5) rate, and (6) private parameters.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3618","Ordinal":"2","NoteData":"2006-07-14","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3618","Ordinal":"3","NoteData":"2018-10-18","Type":"Other","Title":"Modified"}]}}}