CVE-2006-3138
phpMyDirectory <10.4.5 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in phpMyDirectory 10.4.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) PIC parameter in offers-pix.php, (2) from parameter in cp/index.php, and (3) action parameter in cp/admin_index.php.
References (8)
Scores
EPSS
0.0062
EPSS Percentile
69.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (35)
accomplishtechnology/phpmydirectory
< 10.4.5
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
accomplishtechnology/phpmydirectory
... and 20 more
Timeline
Published
Jun 22, 2006
Tracked Since
Feb 18, 2026