Back
CVE-2006-0407
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.
Published: Jan 25, 2006
Modified: Jun 16, 2026
CVSS Metrics
Affected Products (16)
| Vendor | Product | Version |
|---|---|---|
| azbb | az_bulletin_board | 1.0.0 |
| azbb | az_bulletin_board | 1.0.0rc1 |
| azbb | az_bulletin_board | 1.0.0rc2 |
| azbb | az_bulletin_board | 1.0.1 |
| azbb | az_bulletin_board | 1.0.2 |
| azbb | az_bulletin_board | 1.0.3 |
| azbb | az_bulletin_board | 1.0.4 |
| azbb | az_bulletin_board | 1.0.5 |
| azbb | az_bulletin_board | 1.0.6 |
| azbb | az_bulletin_board | 1.0.7 |
| azbb | az_bulletin_board | 1.0.8 |
| azbb | az_bulletin_board | 1.0.9 |
| azbb | az_bulletin_board | 1.0.10 |
| azbb | az_bulletin_board | 1.0.11 |
| azbb | az_bulletin_board | 1.0.12 |
| azbb | az_bulletin_board | 1.1.00 |
GitHub Security Advisory GHSA-g3cc-rr5v-966w
Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and...
References (20)
- http://kapda.ir/advisory-236.html Exploit, Vendor Advisory
- http://secunia.com/advisories/18565 Vendor Advisory
- http://www.securityfocus.com/archive/1/423353/100/0/threaded
- http://www.securityfocus.com/archive/1/423363/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/30/6510/threaded
- http://www.securityfocus.com/archive/1/427194/100/0/threaded
- http://www.securityfocus.com/bid/16351 Exploit
- http://www.vupen.com/english/advisories/2006/0298
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24274
- http://kapda.ir/advisory-236.html Exploit, Vendor Advisory
- http://secunia.com/advisories/18565 Vendor Advisory
- http://www.securityfocus.com/archive/1/423353/100/0/threaded
- http://www.securityfocus.com/archive/1/423363/100/0/threaded
- http://www.securityfocus.com/archive/1/427076/100/0/threaded
Risk Scores
CVSS Score
4.3 / 10
EPSS Score
2.62%
Top 16% most likely to be exploited
Threat Score
18 / 100
Data Sources
NVD
EPSS
GitHub