CVE-2006-1033
Last modified
CVE-2006-1033 is a vulnerability of currently unknown severity. Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.. EPSS estimates a 1.90% chance of exploitation in the next 30 days.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Dragonfly CMS before 9.0.6.1 allow remote attackers to inject arbitrary web script or HTML via (1) uname, (2) error, (3) profile or (4) the username filed parameter to the (a) Your_Account module, (5) catid, (6) sid, (7) Story Text or (8) Extended text text fields in the (b) News module, (9) month, (10) year or (11) sa parameter to the (c) Stories_Archive module, (12) show, (13) cid, (14) ratetype, or (15) orderby parameter to the (d) Web_Links module, (16) op, or (17) pollid parameter to the (e) Surveys module, (18) c parameter to the (f) Downloads module, (19) meta, or (20) album parameter to the (g) coppermine module, or the search box in the (21) Search, (22) Stories_Archive, (23) Downloads, and (24) Topics module.
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cpg-Nuke | Dragonfly Cms | 9.0.1.1 |
| Cpg-Nuke | Dragonfly Cms | 9.0.2.0 |
| Cpg-Nuke | Dragonfly Cms | 9.0.3.0 |
| Cpg-Nuke | Dragonfly Cms | 9.0.4.0 |
| Cpg-Nuke | Dragonfly Cms | 9.0.5.0 |
| Cpg-Nuke | Dragonfly Cms | 9.0.6.0 |
References
- http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18940Vendor Advisory
- http://lostmon.blogspot.com/2006/02/multiple-cross-site-scripting-in.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18940Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-1033?
How severe is CVE-2006-1033?
How do I fix CVE-2006-1033?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2006
- CVE-2006-1027feedcreator.class.php (aka the syndication component) in Joo…
- CVE-2006-1028feedcreator.class.php (aka the syndication component) in Joo…
- CVE-2006-1029The cross-site scripting (XSS) countermeasures in class.inpu…
- CVE-2006-1030Unspecified vulnerability in mod_templatechooser in Joomla! …
- CVE-2006-1031config/config_inc.php in iGENUS Webmail 2.02 and earlier all…
- CVE-2006-1032Eval injection vulnerability in the decode function in rpc_d…
- CVE-2006-1034Multiple cross-site scripting (XSS) vulnerabilities in Woltl…
- CVE-2006-1035Unspecified vulnerability in the Oracle Diagnostics module 2…
- CVE-2006-1036Multiple unspecified vulnerabilities in the Oracle Diagnosti…
- CVE-2006-1037SQL injection vulnerability in the Oracle Diagnostics module…
- CVE-2006-1038Buffer overflow in SecureCRT 5.0.4 and earlier and SecureFX …
- CVE-2006-1039SAP Web Application Server (WebAS) Kernel before 7.0 allows …
Are you affected by CVE-2006-1033?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
