CVE-2006-0927
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a)…
Does this matter?
Lower severity and a low EPSS score (2.09%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the JGS-XA JGS-Gallery Addon 4.0.0 and earlier for Woltlab Burning Board (wBB) 2.x allow remote attackers to inject arbitrary web script or HTML via the (1) userid parameter in (a) jgs_galerie_slideshow.php and (b) jgs_galerie_scroll.php, and the (2) katid parameter in (c) jgs_galerie_slideshow.php.
- CVSS 2.0
- 2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
- EPSS
- 2.09% probability · 81th percentile
- CISA KEV
- Not listed
- Affected
- jgs-xa/jgs-gallery addon · woltlab/burning board
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0615.html
- http://www.nukedx.com/?viewdoc=11Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/425981/100/0/threaded
- http://www.securityfocus.com/bid/16810Vendor Advisory
- http://www.securityfocus.com/bid/16843
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24888
- http://archives.neohapsis.com/archives/fulldisclosure/2006-02/0615.html
- http://www.nukedx.com/?viewdoc=11Exploit, Vendor Advisory
- http://www.securityfocus.com/archive/1/425981/100/0/threaded
- http://www.securityfocus.com/bid/16810Vendor Advisory
- http://www.securityfocus.com/bid/16843
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24888
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.