CVE-2006-0407
Last modified
CVE-2006-0407 is a vulnerability of currently unknown severity. Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. EPSS estimates a 2.56% chance of exploitation in the next 30 days.
Description
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Azbb | Az Bulletin Board | 1.0.0 |
| Azbb | Az Bulletin Board | 1.0.0rc1 |
| Azbb | Az Bulletin Board | 1.0.0rc2 |
| Azbb | Az Bulletin Board | 1.0.1 |
| Azbb | Az Bulletin Board | 1.0.2 |
| Azbb | Az Bulletin Board | 1.0.3 |
| Azbb | Az Bulletin Board | 1.0.4 |
| Azbb | Az Bulletin Board | 1.0.5 |
| Azbb | Az Bulletin Board | 1.0.6 |
| Azbb | Az Bulletin Board | 1.0.7 |
| Azbb | Az Bulletin Board | 1.0.8 |
| Azbb | Az Bulletin Board | 1.0.9 |
| Azbb | Az Bulletin Board | 1.0.10 |
| Azbb | Az Bulletin Board | 1.0.11 |
| Azbb | Az Bulletin Board | 1.0.12 |
| Azbb | Az Bulletin Board | 1.1.00 |
References
- http://kapda.ir/advisory-236.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18565Vendor Advisory
- http://kapda.ir/advisory-236.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18565Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-0407?
How severe is CVE-2006-0407?
How do I fix CVE-2006-0407?
Are you affected by CVE-2006-0407?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
