CVE-2006-5810

XOOPS 1.0 - Cross-Site Scripting via newdownloadshowdays Parameter

Title source: llm
STIX 2.1

Description

Cross-site scripting (XSS) vulnerability in modules/wfdownloads/newlist.php in XOOPS 1.0 allows remote attackers to inject arbitrary web script or HTML via the newdownloadshowdays parameter.

Exploits (1)

exploitdb WRITEUP VERIFIED
by CvIr.System · textwebappsphp
https://www.exploit-db.com/exploits/28914

References (2)

Core 2

Scores

EPSS 0.0035
EPSS Percentile 57.8%

Details

Status published
Products (1)
xoops/xoops 1.0
Published Nov 08, 2006
Tracked Since Feb 18, 2026