Vulnerability Details CVE-2006-3306
Cross-site scripting (XSS) vulnerability in the preparestring function in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web script or HTML via unknown vectors.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 60.6%
CVSS Severity
CVSS v2 Score 4.3
Products affected by CVE-2006-3306
-
cpe:2.3:a:zoid_technologies:project_eros_bbsengine:2006-02-23
-
cpe:2.3:a:zoid_technologies:project_eros_bbsengine:2006-04-29