CVE-2006-6977

Freetextbox - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FreeTextBox allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.

Scores

EPSS 0.0045
EPSS Percentile 63.4%

Classification

CWE
CWE-79
Status draft

Affected Products (1)

freetextbox/freetextbox

Timeline

Published Feb 08, 2007
Tracked Since Feb 18, 2026