CVE-2006-2066

Mkportal - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities pm_popup.php in MKPortal 1.1 Rc1 and earlier, as used with vBulletin 3.5.4 and earlier, allow remote attackers to inject arbitrary web script or HTML via the (1) u1, (2) m1, (3) m2, (4) m3, (5) m4 parameters.

Exploits (1)

exploitdb WORKING POC VERIFIED
by HanowarS · textwebappsphp
https://www.exploit-db.com/exploits/28716

Scores

EPSS 0.0971
EPSS Percentile 92.8%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

mkportal/mkportal

Timeline

Published Apr 27, 2006
Tracked Since Feb 18, 2026