CVE-2006-0194 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 2% (pctl 80)
Patch early
A public exploit exists.
Description
Cross-site scripting (XSS) vulnerability in default.asp in FogBugz 4.029, and other versions before 4.0.33, allows remote attackers to inject arbitrary web script or HTML via the dest parameter in the pgLogon page.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.98% — more likely to be exploited than 80% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-01-13 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| fog creek software | fogbugz |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Fog Creek Software FogBugz 4.0 29 - 'default.asp' Cross-Site Scripting | 2006-01-12 |
References
- http://secunia.com/advisories/18443
- http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html
- http://www.osvdb.org/22370
- http://www.securityfocus.com/archive/1/421729/100/0/threaded
- http://www.securityfocus.com/bid/16216
- http://www.vupen.com/english/advisories/2006/0174
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24103
- http://secunia.com/advisories/18443
- http://www.fogcreek.com/FogBugz/KB/releaseNotes/WhatsNewInFogBugz4.0.33.html
- http://www.osvdb.org/22370
- http://www.securityfocus.com/archive/1/421729/100/0/threaded
- http://www.securityfocus.com/bid/16216
- http://www.vupen.com/english/advisories/2006/0174
- https://exchange.xforce.ibmcloud.com/vulnerabilities/24103
→ the Explorer · watch your stack · NVD