CVE-2006-6401

MyStats <1.0.8 - XSS

Title source: llm

Description

Multiple cross-site scripting (XSS) vulnerabilities in mystats.php in MyStats 1.0.8 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) connexion, (2) by, and (3) details parameter.

Scores

EPSS 0.0136
EPSS Percentile 80.0%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

mystats/mystats < 1.0.8

Timeline

Published Dec 10, 2006
Tracked Since Feb 18, 2026