{"api_version":"1","generated_at":"2026-07-24T17:17:19+00:00","cve":"CVE-2006-3956","urls":{"html":"https://cve.report/CVE-2006-3956","api":"https://cve.report/api/cve/CVE-2006-3956.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-3956","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-3956"},"summary":{"title":"CVE-2006-3956","description":"Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-01 21:04:00","updated_at":"2018-10-17 21:32:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"http://www.vupen.com/english/advisories/2006/3061","name":"ADV-2006-3061","refsource":"VUPEN","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19226","name":"19226","refsource":"BID","tags":[],"title":"Advanced Webhost Billing System Contact.PHP Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/27629","name":"27629","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28069","name":"awbs-contact-xss(28069)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1317","name":"1317","refsource":"SREASON","tags":[],"title":"XSS vulnerability on AWBS - SecurityReason.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/441532/100/0/threaded","name":"20060729 XSS vulnerability on AWBS","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/21296","name":"21296","refsource":"SECUNIA","tags":["Vendor Advisory"],"title":"AWBS Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-3956","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-3956","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"3956","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"total_online_solutions","cpe5":"advanced_webhost_billing_system","cpe6":"2.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"3956","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"total_online_solutions","cpe5":"advanced_webhost_billing_system","cpe6":"2.2.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-3956","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-3061","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/3061"},{"name":"awbs-contact-xss(28069)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28069"},{"name":"20060729 XSS vulnerability on AWBS","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/441532/100/0/threaded"},{"name":"21296","refsource":"SECUNIA","url":"http://secunia.com/advisories/21296"},{"name":"1317","refsource":"SREASON","url":"http://securityreason.com/securityalert/1317"},{"name":"19226","refsource":"BID","url":"http://www.securityfocus.com/bid/19226"},{"name":"27629","refsource":"OSVDB","url":"http://www.osvdb.org/27629"}]}},"nvd":{"publishedDate":"2006-08-01 21:04:00","lastModifiedDate":"2018-10-17 21:32:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:total_online_solutions:advanced_webhost_billing_system:2.2.2:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"3956","Ordinal":"19282","Title":"CVE-2006-3956","CVE":"CVE-2006-3956","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"3956","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in contact.php in Advanced Webhost Billing System (AWBS) 2.2.2 allow remote attackers to inject arbitrary web script or HTML via the (1) Name, (2) AccountUsername and (3) Message parameters.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"3956","Ordinal":"2","NoteData":"2006-08-01","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"3956","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}