{"api_version":"1","generated_at":"2026-07-23T08:17:35+00:00","cve":"CVE-2006-6852","urls":{"html":"https://cve.report/CVE-2006-6852","api":"https://cve.report/api/cve/CVE-2006-6852.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-6852","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-6852"},"summary":{"title":"CVE-2006-6852","description":"Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml.  NOTE: some of these details are obtained from third party information.","state":"PUBLISHED","assigner":"mitre","published_at":"2006-12-31 05:00:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-20","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6","severity":"","vector":"AV:N/AC:M/Au:S/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.securityfocus.com/bid/21811","name":"http://www.securityfocus.com/bid/21811","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"TDiary Unspecified Remote Code Execution Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/23465","name":"http://secunia.com/advisories/23465","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"tDiary Unspecified Ruby Code Execution Vulnerability - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/jp/JVN%2331185550/index.html","name":"http://jvn.jp/jp/JVN%2331185550/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#31185550: tDiary における任意の Ruby スクリプトを実行される脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"http://www.vupen.com/english/advisories/2006/5201","name":"http://www.vupen.com/english/advisories/2006/5201","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.tdiary.org/20061210.html","name":"http://www.tdiary.org/20061210.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"tDiary.org - tDiaryの脆弱性に関する報告(2006-12-10)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/jp/JVN#31185550/index.html","name":"JVN:JVN#31185550","refsource":"MITRE","tags":[],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-6852","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-6852","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"6852","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tdiary","cpe5":"tdiary","cpe6":"2.0.1","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6852","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tdiary","cpe5":"tdiary","cpe6":"2.0.2","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2006","cve_id":"6852","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"tdiary","cpe5":"tdiary","cpe6":"2.0.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:42:07.179Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"ADV-2006-5201","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/5201"},{"name":"JVN#31185550","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/jp/JVN%2331185550/index.html"},{"name":"23465","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/23465"},{"name":"21811","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/21811"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.tdiary.org/20061210.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-12-28T00:00:00.000Z","descriptions":[{"lang":"en","value":"Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml.  NOTE: some of these details are obtained from third party information."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-11T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-5201","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/5201"},{"name":"JVN#31185550","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/jp/JVN%2331185550/index.html"},{"name":"23465","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/23465"},{"name":"21811","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/21811"},{"tags":["x_refsource_MISC"],"url":"http://www.tdiary.org/20061210.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-6852","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml.  NOTE: some of these details are obtained from third party information."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-5201","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/5201"},{"name":"JVN#31185550","refsource":"JVN","url":"http://jvn.jp/jp/JVN%2331185550/index.html"},{"name":"23465","refsource":"SECUNIA","url":"http://secunia.com/advisories/23465"},{"name":"21811","refsource":"BID","url":"http://www.securityfocus.com/bid/21811"},{"name":"http://www.tdiary.org/20061210.html","refsource":"MISC","url":"http://www.tdiary.org/20061210.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-6852","datePublished":"2007-01-04T02:00:00.000Z","dateReserved":"2007-01-03T00:00:00.000Z","dateUpdated":"2024-08-07T20:42:07.179Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2006-12-31 05:00:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-20","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:S/C:P/I:P/A:P","baseScore":6,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":6.8,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:tdiary:tdiary:2.0.1:*:*:*:*:*:*:*","matchCriteriaId":"901E2D28-D124-4633-918B-CDB0EA08C8A2"},{"vulnerable":true,"criteria":"cpe:2.3:a:tdiary:tdiary:2.0.2:*:*:*:*:*:*:*","matchCriteriaId":"A7D4A716-2D1B-47F0-BB24-EC8364CCD5FA"},{"vulnerable":true,"criteria":"cpe:2.3:a:tdiary:tdiary:2.0.3:*:*:*:*:*:*:*","matchCriteriaId":"FD08310D-FF5A-4CFB-866C-9B7308230783"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"6852","Ordinal":"1","Title":"CVE-2006-6852","CVE":"CVE-2006-6852","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"6852","Ordinal":"1","NoteData":"Eval injection vulnerability in tDiary 2.0.3 and 2.1.4.200 61127 allows remote authenticated users to execute arbitrary Ruby code via unspecified vectors, possibly related to incorrect input validation by (1) conf.rhtml and (2) i.conf.rhtml.  NOTE: some of these details are obtained from third party information.","Type":"Description","Title":"CVE-2006-6852"},{"CveYear":"2006","CveId":"6852","Ordinal":"2","NoteData":"2007-01-03","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"6852","Ordinal":"3","NoteData":"2008-11-11","Type":"Other","Title":"Modified"}]}}}