{"api_version":"1","generated_at":"2026-07-23T11:49:35+00:00","cve":"CVE-2006-6148","urls":{"html":"https://cve.report/CVE-2006-6148","api":"https://cve.report/api/cve/CVE-2006-6148.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6148","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6148"},"summary":{"title":"CVE-2006-6148","description":"Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-11-28 23:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/archive/1/452265/100/0/threaded","name":"http://www.securityfocus.com/archive/1/452265/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.frsirt.com/english/reference-2006-4664-1.php","name":"http://www.frsirt.com/english/reference-2006-4664-1.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Félicitations ! Votre domaine a bien été créé chez OVH !","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/21226","name":"http://www.securityfocus.com/bid/21226","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"JiRos Links Manager Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30465","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30465","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securitytracker.com/id?1017280","name":"http://securitytracker.com/id?1017280","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"JiRo's Link Manager Missing Input Validation Permits SQL Injection and Cross-Site Scripting Attacks - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/1924","name":"http://securityreason.com/securityalert/1924","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/23063","name":"http://secunia.com/advisories/23063","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"JiRo's Link Manager Script Insertion and SQL Injection - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4664","name":"http://www.vupen.com/english/advisories/2006/4664","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6148","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6148","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6148","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"jiros","cpe5":"links_manager","cpe6":"1.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:19:34.725Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"jiroslinkmanager-submitlink-xss(30465)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30465"},{"name":"20061121 JiRos Links Manager[injection sql & xss permanent]","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/452265/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.frsirt.com/english/reference-2006-4664-1.php"},{"name":"1017280","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017280"},{"name":"1924","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/1924"},{"name":"21226","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21226"},{"name":"ADV-2006-4664","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4664"},{"name":"23063","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23063"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-17T20:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"jiroslinkmanager-submitlink-xss(30465)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30465"},{"name":"20061121 JiRos Links Manager[injection sql & xss permanent]","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/452265/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://www.frsirt.com/english/reference-2006-4664-1.php"},{"name":"1017280","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017280"},{"name":"1924","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/1924"},{"name":"21226","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21226"},{"name":"ADV-2006-4664","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4664"},{"name":"23063","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23063"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6148","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"jiroslinkmanager-submitlink-xss(30465)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/30465"},{"name":"20061121 JiRos Links Manager[injection sql & xss permanent]","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/452265/100/0/threaded"},{"name":"http://www.frsirt.com/english/reference-2006-4664-1.php","refsource":"MISC","url":"http://www.frsirt.com/english/reference-2006-4664-1.php"},{"name":"1017280","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017280"},{"name":"1924","refsource":"SREASON","url":"http://securityreason.com/securityalert/1924"},{"name":"21226","refsource":"BID","url":"http://www.securityfocus.com/bid/21226"},{"name":"ADV-2006-4664","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4664"},{"name":"23063","refsource":"SECUNIA","url":"http://secunia.com/advisories/23063"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6148","datePublished":"2006-11-28T23:00:00.000Z","dateReserved":"2006-11-28T00:00:00.000Z","dateUpdated":"2024-08-07T20:19:34.725Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-11-28 23:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:jiros:links_manager:1.0:*:*:*:*:*:*:*","matchCriteriaId":"30CFC657-C1B8-4AC5-9C51-6ED1CF226A40"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6148","Ordinal":"1","Title":"CVE-2006-6148","CVE":"CVE-2006-6148","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6148","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in submitlink.asp in JiRos Links Manager allow remote attackers to inject arbitrary web script or HTML via the (1) lName, (2) lURL, (3) lImage, and (4) lDescription parameters.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2006-6148"},{"CveYear":"2006","CveId":"6148","Ordinal":"2","NoteData":"2006-11-28","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6148","Ordinal":"3","NoteData":"2018-10-17","Type":"Other","Title":"Modified"}]}}}