CVE-2006-3138

phpMyDirectory <10.4.5 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action parameter in cp/admin_index.php.

Scores

EPSS 0.0062
EPSS Percentile 69.9%

Classification

CWE
CWE-79
Status draft

Affected Products (35)

accomplishtechnology/phpmydirectory < 10.4.5
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
... and 20 more

Timeline

Published Jun 22, 2006
Tracked Since Feb 18, 2026