{"api_version":"1","generated_at":"2026-07-23T09:21:41+00:00","cve":"CVE-2006-7122","urls":{"html":"https://cve.report/CVE-2006-7122","api":"https://cve.report/api/cve/CVE-2006-7122.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2006-7122","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2006-7122"},"summary":{"title":"CVE-2006-7122","description":"Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-06 01:19:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.8","severity":"","vector":"AV:N/AC:M/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://secunia.com/secunia_research/2006-63/advisory/","name":"http://secunia.com/secunia_research/2006-63/advisory/","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"],"title":"Joomla BSQ Sitestats Component Multiple Vulnerabilities - Secunia Research - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/2360","name":"http://securityreason.com/securityalert/2360","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CXSecurity - IDS","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29266","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29266","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/20267","name":"http://www.securityfocus.com/bid/20267","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"BSQ Sitestats Joomla Component Multiple Input Validation Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.securityfocus.com/archive/1/447356/100/0/threaded","name":"http://www.securityfocus.com/archive/1/447356/100/0/threaded","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2006-7122","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2006-7122","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2006","cve_id":"7122","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"joomla","cpe5":"bsq_sitestats","cpe6":"1.8.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T20:50:06.115Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"bsq-sitestats-ip-xss(29266)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29266"},{"name":"20267","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/20267"},{"name":"2360","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/2360"},{"name":"20060929 Secunia Research: Joomla BSQ Sitestats Component MultipleVulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/447356/100/0/threaded"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://secunia.com/secunia_research/2006-63/advisory/"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-09-29T00:00:00.000Z","descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2018-10-16T14:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"bsq-sitestats-ip-xss(29266)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29266"},{"name":"20267","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/20267"},{"name":"2360","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/2360"},{"name":"20060929 Secunia Research: Joomla BSQ Sitestats Component MultipleVulnerabilities","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/447356/100/0/threaded"},{"tags":["x_refsource_MISC"],"url":"http://secunia.com/secunia_research/2006-63/advisory/"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-7122","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"bsq-sitestats-ip-xss(29266)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/29266"},{"name":"20267","refsource":"BID","url":"http://www.securityfocus.com/bid/20267"},{"name":"2360","refsource":"SREASON","url":"http://securityreason.com/securityalert/2360"},{"name":"20060929 Secunia Research: Joomla BSQ Sitestats Component MultipleVulnerabilities","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/447356/100/0/threaded"},{"name":"http://secunia.com/secunia_research/2006-63/advisory/","refsource":"MISC","url":"http://secunia.com/secunia_research/2006-63/advisory/"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-7122","datePublished":"2007-03-06T01:00:00.000Z","dateReserved":"2007-03-05T00:00:00.000Z","dateUpdated":"2024-08-07T20:50:06.115Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-06 01:19:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":true,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:joomla:bsq_sitestats:1.8.0:*:*:*:*:*:*:*","matchCriteriaId":"FBD756FB-F3A0-4782-8B7E-D8B4BC6E339C"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2006","CveId":"7122","Ordinal":"1","Title":"CVE-2006-7122","CVE":"CVE-2006-7122","Year":"2006"},"notes":[{"CveYear":"2006","CveId":"7122","Ordinal":"1","NoteData":"Cross-site scripting (XSS) vulnerability in the IP Address Lookup functionality in BSQ Sitestats (component for Joomla) 1.8.0, and possibly other versions before 2.2.1, allows remote attackers to inject arbitrary web script and HTML via the ip parameter.","Type":"Description","Title":"CVE-2006-7122"},{"CveYear":"2006","CveId":"7122","Ordinal":"2","NoteData":"2007-03-05","Type":"Other","Title":"Published"},{"CveYear":"2006","CveId":"7122","Ordinal":"3","NoteData":"2018-10-16","Type":"Other","Title":"Modified"}]}}}