CVE-2006-6746
Xt-News 0.1 - XSS
Title source: llmDescription
Multiple cross-site scripting (XSS) vulnerabilities in Xt-News 0.1 allow remote attackers to inject arbitrary web script or HTML via the id_news parameter to (1) add_comment.php or (2) show_news.php.
Exploits (2)
References (6)
Scores
EPSS
0.0506
EPSS Percentile
89.6%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
dreaxteam/xt-news
Timeline
Published
Dec 27, 2006
Tracked Since
Feb 18, 2026