SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2006-3620

Cross-site scripting (XSS) vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web script or HTML via the toid parameter.

LOW 2.6EPSS 1.22%

Does this matter?

Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.

Description

Cross-site scripting (XSS) vulnerability in the showtopic module in Koobi Pro CMS 5.6 allows remote attackers to inject arbitrary web script or HTML via the toid parameter.

CVSS 2.0
2.6 LOWAV:N/AC:H/Au:N/C:N/I:P/A:N
EPSS
1.22% probability · 67th percentile
CISA KEV
Not listed
Affected
dream4/koobi pro
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.