CVE-2006-3306

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
29/06/2006
Last modified:
03/04/2025

Description

Cross-site scripting (XSS) vulnerability in the preparestring function in lib/common.php in Project EROS bbsengine before 20060501-0142-jam, and possibly earlier versions dating back to 2006-02-23, might allow remote attackers to inject arbitrary web script or HTML via unknown vectors.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zoid_technologies:project_eros_bbsengine:*:*:*:*:*:*:*:* 2006-04-29 (including)
cpe:2.3:a:zoid_technologies:project_eros_bbsengine:2006-02-23:*:*:*:*:*:*:*