CVE-2006-0938
EZ Publish < 3.7.3 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in eZ publish 3.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the RefererURL parameter.
References (5)
Scores
EPSS
0.0050
EPSS Percentile
65.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (16)
ez/ez_publish
< 3.7.3
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
ez/ez_publish
... and 1 more
Timeline
Published
Mar 01, 2006
Tracked Since
Feb 18, 2026