CVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter.
Does this matter?
Lower severity and a low EPSS score (2.62%). Track it; it rarely justifies an emergency change on its own.
Description
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 2.62% probability · 85th percentile
- CISA KEV
- Not listed
- Affected
- azbb/az bulletin board
- Source
- cve@mitre.org
References
- http://kapda.ir/advisory-236.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18565Vendor Advisory
- http://www.securityfocus.com/archive/1/423353/100/0/threaded
- http://www.securityfocus.com/archive/1/423363/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/30/6510/threaded
- http://www.securityfocus.com/archive/1/427194/100/0/threaded
- http://www.securityfocus.com/bid/16351Exploit
- http://www.vupen.com/english/advisories/2006/0298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24274
- http://kapda.ir/advisory-236.htmlExploit, Vendor Advisory
- http://secunia.com/advisories/18565Vendor Advisory
- http://www.securityfocus.com/archive/1/423353/100/0/threaded
- http://www.securityfocus.com/archive/1/423363/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/30/6510/threaded
- http://www.securityfocus.com/archive/1/427194/100/0/threaded
- http://www.securityfocus.com/bid/16351Exploit
- http://www.vupen.com/english/advisories/2006/0298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24274
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.