CVE Vulnerabilities

CVE-2006-6040

Published: Nov 22, 2006 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.

Affected Software

NameVendorStart VersionEnd Version
VbulletinJelsoft3.6.0 (including)3.6.0 (including)
VbulletinJelsoft3.6.1 (including)3.6.1 (including)
VbulletinJelsoft3.6.2 (including)3.6.2 (including)
VbulletinJelsoft3.6.3 (including)3.6.3 (including)

References