{"api_version":"1","generated_at":"2026-07-23T13:57:04+00:00","cve":"CVE-2006-6082","urls":{"html":"https://cve.report/CVE-2006-6082","api":"https://cve.report/api/cve/CVE-2006-6082.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6082","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6082"},"summary":{"title":"CVE-2006-6082","description":"Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-11-24 18:07:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"4.3","severity":"","vector":"AV:N/AC:M/Au:N/C:N/I:P/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"}}],"references":[{"url":"http://www.securityfocus.com/bid/21230","name":"http://www.securityfocus.com/bid/21230","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Creascripts Creadirectory Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54","name":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory","URL Repurposed"],"title":"s-a-p.ca","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1907","name":"http://securityreason.com/securityalert/1907","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"creadirectory [injection sql & xss] - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30473","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30473","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/452241/100/0/threaded","name":"http://www.securityfocus.com/archive/1/452241/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4665","name":"http://www.vupen.com/english/advisories/2006/4665","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23067","name":"http://secunia.com/advisories/23067","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"],"title":"CreaDirectory Cross-Site Scripting and SQL Injections - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6082","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6082","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6082","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"creascripts","cpe5":"creadirectory","cpe6":"1.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:12:31.818Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"21230","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21230"},{"name":"ADV-2006-4665","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4665"},{"name":"creadirectory-addlisting-search-xss(30473)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30473"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54"},{"name":"23067","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23067"},{"name":"1907","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/1907"},{"name":"20061121 creadirectory [injection sql & xss]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/452241/100/0/threaded"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"21230","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21230"},{"name":"ADV-2006-4665","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4665"},{"name":"creadirectory-addlisting-search-xss(30473)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30473"},{"tags":["x_refsource_MISC"],"url":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54"},{"name":"23067","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23067"},{"name":"1907","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/1907"},{"name":"20061121 creadirectory [injection sql & xss]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/452241/100/0/threaded"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6082","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"21230","refsource":"BID","url":"http://www.securityfocus.com/bid/21230"},{"name":"ADV-2006-4665","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4665"},{"name":"creadirectory-addlisting-search-xss(30473)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30473"},{"name":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54","refsource":"MISC","url":"http://s-a-p.ca/index.php?page=OurAdvisories&id=54"},{"name":"23067","refsource":"SECUNIA","url":"http://secunia.com/advisories/23067"},{"name":"1907","refsource":"SREASON","url":"http://securityreason.com/securityalert/1907"},{"name":"20061121 creadirectory [injection sql & xss]","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/452241/100/0/threaded"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6082","datePublished":"2006-11-24T18:00:00.000Z","dateReserved":"2006-11-24T00:00:00.000Z","dateUpdated":"2024-08-07T20:12:31.818Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-11-24 18:07:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:N/I:P/A:N","baseScore":4.3,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"NONE","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:creascripts:creadirectory:1.2:*:*:*:*:*:*:*","matchCriteriaId":"2A5B6ABB-1307-4C9E-BA68-AF99F4FE1C97"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6082","Ordinal":"1","Title":"CVE-2006-6082","CVE":"CVE-2006-6082","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6082","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in CreaScripts Creadirectory allow remote attackers to inject arbitrary web script or HTML via the (1) cat parameter to addlisting.asp or the (2) search parameter to search.asp.","Type":"Description","Title":"CVE-2006-6082"},{"CveYear":"2006","CveId":"6082","Ordinal":"2","NoteData":"2006-11-24","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6082","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}