CVE-2006-5239
Expblog < 0.3.5 - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in eXpBlog 0.3.5 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the query string (PHP_SELF) in kalender.php or (2) the captcha_session_code parameter in pre_details.php.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Tamriel · textwebappsphp
https://www.exploit-db.com/exploits/28776
References (8)
Scores
EPSS
0.0795
EPSS Percentile
91.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
expblog/expblog
< 0.3.5
Timeline
Published
Oct 12, 2006
Tracked Since
Feb 18, 2026