CVE-2006-6108
Ec-cube - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in EC-CUBE before 1.0.1a-beta allows remote attackers to inject arbitrary web script or HTML via unknown attack vectors.
References (6)
Scores
EPSS
0.0053
EPSS Percentile
66.8%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
ec-cube/ec-cube
Timeline
Published
Nov 26, 2006
Tracked Since
Feb 18, 2026