CVE-2006-2951

NPDS 5.10 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in Net Portal Dynamic System (NPDS) 5.10 and earlier allow remote attackers to inject arbitrary web script and HTML via the (1) Titlesitename or (2) sitename parameter to (a) header.php, (3) nuke_url parameter to (b) meta/meta.php, (4) forum parameter to (c) viewforum.php, (5) post_id, (6) forum, (7) topic, or (8) arbre parameter to (d) editpost.php, or (9) uname or (10) email parameter to (e) user.php.

Scores

EPSS 0.0611
EPSS Percentile 90.6%

Classification

CWE
CWE-79
Status draft

Affected Products (3)

npds/npds < 5.10
npds/npds
npds/npds

Timeline

Published Jun 12, 2006
Tracked Since Feb 18, 2026