CVE-2006-6978
Fckeditor - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.
Scores
EPSS
0.0045
EPSS Percentile
63.4%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
fckeditor/fckeditor
Timeline
Published
Feb 08, 2007
Tracked Since
Feb 18, 2026