CVE-2006-1661

SKForum <1.5 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID parameter in user.View.action.

Exploits (3)

exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27572
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27571
exploitdb WRITEUP VERIFIED
by r0t · textwebappsphp
https://www.exploit-db.com/exploits/27573

Scores

EPSS 0.0074
EPSS Percentile 72.6%

Classification

Status draft

Affected Products (1)

sk_soft/skforum < 1.5

Timeline

Published Apr 07, 2006
Tracked Since Feb 18, 2026