CVE-2007-6616
SimpleForum <4.6.2 - XSS
Title source: llmDescription
Cross-site scripting (XSS) vulnerability in simpleforum.cgi in SimpleForum 4.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the searchkey parameter in a search action. NOTE: some of these details are obtained from third party information.
References (5)
Scores
EPSS
0.0033
EPSS Percentile
55.5%
Classification
CWE
CWE-79
Status
draft
Affected Products (1)
simpleforum/simpleforum
< 4.6.2
Timeline
Published
Jan 03, 2008
Tracked Since
Feb 18, 2026