{"api_version":"1","generated_at":"2026-07-23T13:13:17+00:00","cve":"CVE-2006-3765","urls":{"html":"https://cve.report/CVE-2006-3765","api":"https://cve.report/api/cve/CVE-2006-3765.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3765","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3765"},"summary":{"title":"CVE-2006-3765","description":"Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the \"name input\" field in new_entry.php.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-07-21 14:03:00","updated_at":"2018-10-17 21:29:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/2871","name":"ADV-2006-2871","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19053","name":"19053","refsource":"BID","tags":[],"title":"hdweGUEST Multiple HTML Injection Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://securitytracker.com/id?1016549","name":"1016549","refsource":"SECTRACK","tags":[],"title":"SecurityTracker.com Archives - hwdeGUEST Input Validation Hole in 'new_entry.php' Permits Cross-Site Scripting Attacks","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/440455/100/0/threaded","name":"20060718 hdweGUEST <= 2.1.1 Cross Site Scripting Vulnerabilities","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27805","name":"hwdeguest-newentry-xss(27805)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1258","name":"1258","refsource":"SREASON","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3765","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3765","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3765","vulnerable":"1","versionEndIncluding":"2.1.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"huttenlocher_webdesign","cpe5":"hwdeguest","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3765","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the \"name input\" field in new_entry.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"1016549","refsource":"SECTRACK","url":"http://securitytracker.com/id?1016549"},{"name":"ADV-2006-2871","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2871"},{"name":"20060718 hdweGUEST <= 2.1.1 Cross Site Scripting Vulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/440455/100/0/threaded"},{"name":"19053","refsource":"BID","url":"http://www.securityfocus.com/bid/19053"},{"name":"1258","refsource":"SREASON","url":"http://securityreason.com/securityalert/1258"},{"name":"hwdeguest-newentry-xss(27805)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27805"}]}},"nvd":{"publishedDate":"2006-07-21 14:03:00","lastModifiedDate":"2018-10-17 21:29:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:huttenlocher_webdesign:hwdeguest:*:*:*:*:*:*:*:*","versionEndIncluding":"2.1.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3765","Ordinal":"19091","Title":"CVE-2006-3765","CVE":"CVE-2006-3765","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3765","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in Huttenlocher Webdesign hwdeGUEST 2.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated by the \"name input\" field in new_entry.php.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3765","Ordinal":"2","NoteData":"2006-07-20","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3765","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}