{"api_version":"1","generated_at":"2026-07-23T10:23:48+00:00","cve":"CVE-2006-6401","urls":{"html":"https://cve.report/CVE-2006-6401","api":"https://cve.report/api/cve/CVE-2006-6401.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6401","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6401"},"summary":{"title":"CVE-2006-6401","description":"Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-10 02:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-79","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://securitytracker.com/id?1017210","name":"http://securitytracker.com/id?1017210","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory","VDB Entry"],"title":"myStats Permits Cross-Site Scripting and SQL Injection Attacks and Discloses the Installation Path to Remote Users - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.osvdb.org/30319","name":"http://www.osvdb.org/30319","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Broken Link"],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://marc.info/?l=bugtraq&m=116344068502988&w=2","name":"http://marc.info/?l=bugtraq&m=116344068502988&w=2","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"],"title":"","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/4468","name":"http://www.vupen.com/english/advisories/2006/4468","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Not Applicable"],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/22813","name":"http://secunia.com/advisories/22813","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6401","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6401","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6401","vulnerable":"1","versionEndIncluding":"1.0.8","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"mystats","cpe5":"mystats","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:26:46.367Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"22813","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/22813"},{"name":"1017210","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://securitytracker.com/id?1017210"},{"name":"30319","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://www.osvdb.org/30319"},{"name":"20061112 MyStats <=1.0.8 [injection sql, multiples xss, array & full path","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://marc.info/?l=bugtraq&m=116344068502988&w=2"},{"name":"ADV-2006-4468","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/4468"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-11-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2016-10-17T13:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"22813","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/22813"},{"name":"1017210","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://securitytracker.com/id?1017210"},{"name":"30319","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://www.osvdb.org/30319"},{"name":"20061112 MyStats <=1.0.8 [injection sql, multiples xss, array & full path","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://marc.info/?l=bugtraq&m=116344068502988&w=2"},{"name":"ADV-2006-4468","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/4468"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6401","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"22813","refsource":"SECUNIA","url":"http://secunia.com/advisories/22813"},{"name":"1017210","refsource":"SECTRACK","url":"http://securitytracker.com/id?1017210"},{"name":"30319","refsource":"OSVDB","url":"http://www.osvdb.org/30319"},{"name":"20061112 MyStats <=1.0.8 [injection sql, multiples xss, array & full path","refsource":"BUGTRAQ","url":"http://marc.info/?l=bugtraq&m=116344068502988&w=2"},{"name":"ADV-2006-4468","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/4468"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6401","datePublished":"2006-12-10T02:00:00.000Z","dateReserved":"2006-12-09T00:00:00.000Z","dateUpdated":"2024-08-07T20:26:46.367Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-10 02:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-79","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:mystats:mystats:*:*:*:*:*:*:*:*","versionEndIncluding":"1.0.8","matchCriteriaId":"80360CC1-BA7F-4B0E-A8B6-07245411FB15"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6401","Ordinal":"1","Title":"CVE-2006-6401","CVE":"CVE-2006-6401","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6401","Ordinal":"1","NoteData":"Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter.","Type":"Description","Title":"CVE-2006-6401"},{"CveYear":"2006","CveId":"6401","Ordinal":"2","NoteData":"2006-12-09","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6401","Ordinal":"3","NoteData":"2016-10-17","Type":"Other","Title":"Modified"}]}}}