{"api_version":"1","generated_at":"2026-07-23T12:24:09+00:00","cve":"CVE-2006-5534","urls":{"html":"https://cve.report/CVE-2006-5534","api":"https://cve.report/api/cve/CVE-2006-5534.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-5534","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-5534"},"summary":{"title":"CVE-2006-5534","description":"Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-10-26 17:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.osvdb.org/30016","name":"http://www.osvdb.org/30016","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/22571","name":"http://secunia.com/advisories/22571","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Zwahlen Online Shop Cross-Site Scripting Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://attrition.org/pipermail/vim/2006-November/001106.html","name":"http://attrition.org/pipermail/vim/2006-November/001106.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"[VIM] Zwahlen Online Shop","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4160","name":"http://www.vupen.com/english/advisories/2006/4160","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-5534","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-5534","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"5534","vulnerable":"1","versionEndIncluding":"5.2.2.50","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"zwahlen_informatik","cpe5":"online_shop","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T19:55:53.199Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-4160","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4160"},{"name":"30016","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30016"},{"name":"22571","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22571"},{"name":"20061103 Zwahlen Online Shop","tags":["mailing-list","x_refsource_VIM","x_transferred"],"url":"http://attrition.org/pipermail/vim/2006-November/001106.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-10-24T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2006-11-09T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-4160","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4160"},{"name":"30016","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30016"},{"name":"22571","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22571"},{"name":"20061103 Zwahlen Online Shop","tags":["mailing-list","x_refsource_VIM"],"url":"http://attrition.org/pipermail/vim/2006-November/001106.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-5534","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-4160","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4160"},{"name":"30016","refsource":"OSVDB","url":"http://www.osvdb.org/30016"},{"name":"22571","refsource":"SECUNIA","url":"http://secunia.com/advisories/22571"},{"name":"20061103 Zwahlen Online Shop","refsource":"VIM","url":"http://attrition.org/pipermail/vim/2006-November/001106.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-5534","datePublished":"2006-10-26T17:00:00.000Z","dateReserved":"2006-10-26T00:00:00.000Z","dateUpdated":"2024-08-07T19:55:53.199Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-10-26 17:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:zwahlen_informatik:online_shop:*:*:*:*:*:*:*:*","versionEndIncluding":"5.2.2.50","matchCriteriaId":"8ECF4D86-2482-4EAC-B136-A0F8E1466810"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"5534","Ordinal":"1","Title":"CVE-2006-5534","CVE":"CVE-2006-5534","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"5534","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in index.htm in Zwahlen Online Shop Freeware 5.2.2.50, and possibly earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) cat, (2) Kat, (3) id, or (4) no parameters. NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2006-5534"},{"CveYear":"2006","CveId":"5534","Ordinal":"2","NoteData":"2006-10-26","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"5534","Ordinal":"3","NoteData":"2006-11-09","Type":"Other","Title":"Modified"}]}}}