{"api_version":"1","generated_at":"2026-07-23T08:30:57+00:00","cve":"CVE-2006-4293","urls":{"html":"https://cve.report/CVE-2006-4293","api":"https://cve.report/api/cve/CVE-2006-4293.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-4293","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-4293"},"summary":{"title":"CVE-2006-4293","description":"Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2006-08-22 17:04:00","updated_at":"2018-10-17 21:34:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28447","name":"cpanel-dohtaccess-xss(28447)","refsource":"XF","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/28042","name":"28042","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/443637/100/0/threaded","name":"20060816 Multiple xxs cPanel 10","refsource":"BUGTRAQ","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/19624","name":"19624","refsource":"BID","tags":[],"title":"CPanel Multiple Cross-Site Scripting Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.osvdb.org/28041","name":"28041","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/21592","name":"21592","refsource":"SECUNIA","tags":["Exploit","Vendor Advisory"],"title":"cPanel Multiple Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1442","name":"1442","refsource":"SREASON","tags":[],"title":"SecurityReason - Multiple xxs cPanel 10","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/28043","name":"28043","refsource":"OSVDB","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-4293","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-4293","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"4293","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cpanel","cpe5":"cpanel","cpe6":"10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"4293","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cpanel","cpe5":"cpanel","cpe6":"10","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-4293","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"cpanel-dohtaccess-xss(28447)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/28447"},{"name":"28043","refsource":"OSVDB","url":"http://www.osvdb.org/28043"},{"name":"19624","refsource":"BID","url":"http://www.securityfocus.com/bid/19624"},{"name":"21592","refsource":"SECUNIA","url":"http://secunia.com/advisories/21592"},{"name":"20060816 Multiple xxs cPanel 10","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/443637/100/0/threaded"},{"name":"28041","refsource":"OSVDB","url":"http://www.osvdb.org/28041"},{"name":"1442","refsource":"SREASON","url":"http://securityreason.com/securityalert/1442"},{"name":"28042","refsource":"OSVDB","url":"http://www.osvdb.org/28042"}]}},"nvd":{"publishedDate":"2006-08-22 17:04:00","lastModifiedDate":"2018-10-17 21:34:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE","baseScore":4.3},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:cpanel:cpanel:10:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"4293","Ordinal":"19625","Title":"CVE-2006-4293","CVE":"CVE-2006-4293","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"4293","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in cPanel 10 allow remote attackers to inject arbitrary web script or HTML via the (1) dir parameter in dohtaccess.html, or the (2) file parameter in (a) editit.html or (b) showfile.html.","Type":"Description","Title":null},{"CveYear":"2006","CveId":"4293","Ordinal":"2","NoteData":"2006-08-22","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"4293","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}