{"api_version":"1","generated_at":"2026-07-23T08:54:50+00:00","cve":"CVE-2006-7050","urls":{"html":"https://cve.report/CVE-2006-7050","api":"https://cve.report/api/cve/CVE-2006-7050.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-7050","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-7050"},"summary":{"title":"CVE-2006-7050","description":"Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-02-24 00:28:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27227","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27227","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/18481","name":"http://www.securityfocus.com/bid/18481","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Wikkawiki Wakka.PHP Cross-Site Scripting Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://wush.net/trac/wikka/changeset/47","name":"http://wush.net/trac/wikka/changeset/47","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Changeset 47 – WikkaWiki Tracker","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://wikkawiki.org/WikkaReleaseNotes","name":"http://wikkawiki.org/WikkaReleaseNotes","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Wikka:  Release Notes","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://wush.net/trac/wikka/ticket/142","name":"http://wush.net/trac/wikka/ticket/142","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"#142 (Javascript not stripped from forced links)\n     – WikkaWiki Tracker","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2006/2381","name":"http://www.vupen.com/english/advisories/2006/2381","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"inode/x-empty","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/20628","name":"http://secunia.com/advisories/20628","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Wikkawiki Two Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-7050","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-7050","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"7050","vulnerable":"1","versionEndIncluding":"1.1.6.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"wikkawiki","cpe5":"wikkawiki","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:50:06.182Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wikkawiki.org/WikkaReleaseNotes"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wush.net/trac/wikka/changeset/47"},{"name":"ADV-2006-2381","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/2381"},{"name":"20628","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/20628"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://wush.net/trac/wikka/ticket/142"},{"name":"wikkawiki-url-xss(27227)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27227"},{"name":"18481","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/18481"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-06-12T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://wikkawiki.org/WikkaReleaseNotes"},{"tags":["x_refsource_CONFIRM"],"url":"http://wush.net/trac/wikka/changeset/47"},{"name":"ADV-2006-2381","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/2381"},{"name":"20628","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/20628"},{"tags":["x_refsource_CONFIRM"],"url":"http://wush.net/trac/wikka/ticket/142"},{"name":"wikkawiki-url-xss(27227)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27227"},{"name":"18481","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/18481"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-7050","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://wikkawiki.org/WikkaReleaseNotes","refsource":"CONFIRM","url":"http://wikkawiki.org/WikkaReleaseNotes"},{"name":"http://wush.net/trac/wikka/changeset/47","refsource":"CONFIRM","url":"http://wush.net/trac/wikka/changeset/47"},{"name":"ADV-2006-2381","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/2381"},{"name":"20628","refsource":"SECUNIA","url":"http://secunia.com/advisories/20628"},{"name":"http://wush.net/trac/wikka/ticket/142","refsource":"CONFIRM","url":"http://wush.net/trac/wikka/ticket/142"},{"name":"wikkawiki-url-xss(27227)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27227"},{"name":"18481","refsource":"BID","url":"http://www.securityfocus.com/bid/18481"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-7050","datePublished":"2007-02-24T00:00:00.000Z","dateReserved":"2007-02-23T00:00:00.000Z","dateUpdated":"2024-08-07T20:50:06.182Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-02-24 00:28:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:wikkawiki:wikkawiki:*:*:*:*:*:*:*:*","versionEndIncluding":"1.1.6.1","matchCriteriaId":"98ABA654-0C36-4611-87A0-4DC94592BB17"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"7050","Ordinal":"1","Title":"CVE-2006-7050","CVE":"CVE-2006-7050","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"7050","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.","Type":"Description","Title":"CVE-2006-7050"},{"CveYear":"2006","CveId":"7050","Ordinal":"2","NoteData":"2007-02-23","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"7050","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}