CVE-2006-3366

V3 Chat - XSS

Title source: llm
STIX 2.1

Description

Multiple cross-site scripting (XSS) vulnerabilities in V3 Chat allow remote attackers to inject arbitrary web script or HTML via crafted HTML tags, as demonstrated by the IMG tag, in the (1) id parameter in (a) mail/index.php and (b) mail/reply.php; (2) login_id parameter in (c) members/is_online.php; (3) site_id parameter in (d) messenger/online.php, (e) messenger/search.php, and (f) messenger/profile.php; (4) contact_name parameter in messenger/search.php; (5) membername parameter in (g) messenger/profileview.php; (6) unspecified parameters used when "editing a profile"; and (7) cust_name parameter in (h) messenger/expire.php. NOTE: The vendor disputes the vectors involving files in the messenger directory, stating "... the referenced folder 'messenger' was never available to the general public...".

Exploits (7)

exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28071
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28073
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28072
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28070
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28074
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28069
exploitdb WORKING POC VERIFIED
by Luny · textwebappsphp
https://www.exploit-db.com/exploits/28068

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18543
Exploit vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016340
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/437755/100/200/threaded
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2474
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/438069/100/200/threaded

Scores

EPSS 0.0049
EPSS Percentile 65.4%

Details

Status published
Products (1)
v3_chat/v3_chat beta
Published Jul 06, 2006
Tracked Since Feb 18, 2026