← All CVEs

CVE-2006-6421

medium · 6

Cross-site scripting (XSS) vulnerability in the private message box implementation (privmsg.php) in phpBB 2.0.x allows remote authenticated users to inject arbitrary web script or HTML via the "Message body" field in a message to a non-existent user.

6
CVSS
15.6%
EPSS (exploit prob.)
97th
EPSS percentile
2006-12-10
Published

AV:N/AC:M/Au:S/C:P/I:P/A:P

Affected products

VendorProductAffected versions
phpbb_groupphpbb2.0
phpbb_groupphpbb2.0.0
phpbb_groupphpbb2.0.1
phpbb_groupphpbb2.0.2
phpbb_groupphpbb2.0.3
phpbb_groupphpbb2.0.4
phpbb_groupphpbb2.0.5
phpbb_groupphpbb2.0.6
phpbb_groupphpbb2.0.6c
phpbb_groupphpbb2.0.6d
phpbb_groupphpbb2.0.7
phpbb_groupphpbb2.0.7a
phpbb_groupphpbb2.0.8
phpbb_groupphpbb2.0.8a
phpbb_groupphpbb2.0.9
phpbb_groupphpbb2.0.10
phpbb_groupphpbb2.0.11
phpbb_groupphpbb2.0.12
phpbb_groupphpbb2.0.13
phpbb_groupphpbb2.0.14
phpbb_groupphpbb2.0.15
phpbb_groupphpbb2.0.16
phpbb_groupphpbb2.0.17
phpbb_groupphpbb2.0.18
phpbb_groupphpbb2.0.19
phpbb_groupphpbb2.0.20
phpbb_groupphpbb2.0.21
phpbb_groupphpbb2.0_beta1
phpbb_groupphpbb2.0_rc1
phpbb_groupphpbb2.0_rc2
phpbb_groupphpbb2.0_rc3
phpbb_groupphpbb2.0_rc4

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2006-6421