{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-02T13:43:13.964","vulnerabilities":[{"cve":{"id":"CVE-2006-3617","sourceIdentifier":"cve@mitre.org","published":"2006-07-18T15:46:00.000","lastModified":"2026-06-16T22:27:25.787","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cross-site scripting (XSS) vulnerability in pblguestbook.php in Pixelated By Lev (PBL) Guestbook 1.32 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) name, (2) message (aka comments), (3) website, and (4) email parameters, which bypasses XSS protection mechanisms that check for SCRIPT tags but not others, as demonstrated by a javascript URI in an onMouseOver attribute and the src attribute in an iframe tag.  NOTE: some vectors might overlap CVE-2006-2975, although the use of alternate manipulations makes it unclear."},{"lang":"es","value":"Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en pblguestbook.php en Pixelated By Lev (PBL) Guestbook 1.32 y anteriores permite a atacantes remotos inyectar secuencias de comandos web o HTML a través de los parámetros (1) name, (2) message (aka comments), (3) website, y (4) email, el cual evita el mecanismo de protección XSS que valida para la etiquetas del SCRIPT pero otras no, como se demostró con el URI javascript en un atributo onMouseOver y el atributo src en una etiqueta iframe. NOTA: algunos vectores podrían solaparse con CVE-2006-2975, aunque el uso de manipulaciones alternativas lo hacen poco claro."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"n/a","product":"n/a","versions":[{"version":"n/a","status":"affected"}]}]}],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:N","baseScore":5.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":4.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:pixelated_by_lev:pixelated_by_lev_guestbook:1.32:*:*:*:*:*:*:*","matchCriteriaId":"4B430F99-CFB3-420B-BBC8-9587B5317B55"}]}]}],"references":[{"url":"http://www.neosecurityteam.net/index.php?action=advisories&id=23","source":"cve@mitre.org","tags":["Exploit","Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/439486/100/0/threaded","source":"cve@mitre.org"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27006","source":"cve@mitre.org"},{"url":"http://www.neosecurityteam.net/index.php?action=advisories&id=23","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Vendor Advisory"]},{"url":"http://www.securityfocus.com/archive/1/439486/100/0/threaded","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/27006","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}