CVE-2006-7059
Scriptsez.net E-dating System - XSS
Title source: ruleDescription
Multiple cross-site scripting (XSS) vulnerabilities in Scriptsez.net E-Dating System allow remote attackers to inject arbitrary web script or HTML via encoded entities (') in IMG tags to (1) messages, (2) profile fields, or (3) the id parameter in a dologin operation to cindex.php.
References (5)
Scores
EPSS
0.0043
EPSS Percentile
61.9%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
scriptsez.net/e-dating_system
Timeline
Published
Feb 24, 2007
Tracked Since
Feb 18, 2026