CVE-2006-3240
dotProject <2.0.3 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in classes/ui.class.php in dotProject 2.0.3 and earlier allows remote attackers to inject arbitrary web script or HTML via the login parameter.
References (7)
Scores
EPSS
0.0063
EPSS Percentile
70.1%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
dotproject/dotproject
< 2.0.3
Timeline
Published
Jun 27, 2006
Tracked Since
Feb 18, 2026