CVE-2006-1196

QwikiWiki 1.5 - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in QwikiWiki 1.5 allow remote attackers to inject arbitrary web script or HTML via the (1) from and (2) help parameters to (a) index.php; (3) action, (4) page, (5) debug, (6) help, (7) username, or (8) password parameters to (b) login.php; the (7) help parameter to (c) pageindex.php; or (8) help parameter to (d) recentchanges.php.

Exploits (4)

exploitdb WRITEUP VERIFIED
by Kiki · textwebappsphp
https://www.exploit-db.com/exploits/27412
exploitdb WRITEUP VERIFIED
by Kiki · textwebappsphp
https://www.exploit-db.com/exploits/27411
exploitdb WORKING POC VERIFIED
by Kiki · textwebappsphp
https://www.exploit-db.com/exploits/27410
exploitdb WRITEUP VERIFIED
by Kiki · textwebappsphp
https://www.exploit-db.com/exploits/27409

References (9)

Core 9
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23788
Exploit, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/19182
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/17064
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23789
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25128
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23786
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/0910
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/23787

Scores

EPSS 0.0103
EPSS Percentile 77.4%

Details

Status published
Products (3)
david_barrett/qwikiwiki 1.4
david_barrett/qwikiwiki 1.5
david_barrett/qwikiwiki 1.5.1
Published Mar 13, 2006
Tracked Since Feb 18, 2026