CVE-2006-3385
Vincent Leclercq News 5.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in divers.php in Vincent Leclercq News 5.2 allows remote attackers to inject arbitrary web script or HTML via the (1) id and (2) disabled parameters.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by DarkFig · textwebappsphp
https://www.exploit-db.com/exploits/28146
References (6)
Scores
EPSS
0.0062
EPSS Percentile
69.7%
Classification
Status
draft
Affected Products (1)
vincent_leclercq/news
Timeline
Published
Jul 06, 2006
Tracked Since
Feb 18, 2026