Back

CVE-2006-0407

Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) nickname parameter and (2) an iframe tag in the topic parameter. NOTE: the original disclosure specified the name parameter, but a correction was later provided. NOTE: followup posts have both disputed and confirmed the original claim.

Published: Jan 25, 2006 Modified: Jun 16, 2026

CVSS Metrics

Affected Products (16)

Vendor Product Version
azbb az_bulletin_board 1.0.0
azbb az_bulletin_board 1.0.0rc1
azbb az_bulletin_board 1.0.0rc2
azbb az_bulletin_board 1.0.1
azbb az_bulletin_board 1.0.2
azbb az_bulletin_board 1.0.3
azbb az_bulletin_board 1.0.4
azbb az_bulletin_board 1.0.5
azbb az_bulletin_board 1.0.6
azbb az_bulletin_board 1.0.7
azbb az_bulletin_board 1.0.8
azbb az_bulletin_board 1.0.9
azbb az_bulletin_board 1.0.10
azbb az_bulletin_board 1.0.11
azbb az_bulletin_board 1.0.12
azbb az_bulletin_board 1.1.00

GitHub Security Advisory GHSA-g3cc-rr5v-966w

Cross-site scripting (XSS) vulnerability in post.php in AZ Bulletin Board (AZbb) 1.1.00 and...

Risk Scores

CVSS Score 4.3 / 10
EPSS Score 2.62%

Top 16% most likely to be exploited

Threat Score 18 / 100

Data Sources

NVD EPSS GitHub