CVE-2006-6159

Deskpro - XSS

Title source: rule

Description

Multiple cross-site scripting (XSS) vulnerabilities in newticket.php in DeskPRO 2.0.0 and 2.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) message or (2) subject parameter.

Scores

EPSS 0.0172
EPSS Percentile 82.2%

Classification

CWE
CWE-79
Status draft

Affected Products (2)

deskpro/deskpro
deskpro/deskpro

Timeline

Published Nov 28, 2006
Tracked Since Feb 18, 2026