peter bassill · operator
$ cve CVE-2006-0217 JSON

CVE-2006-0217 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.2% (pctl 82)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in Ultimate Auction 3.67 allow remote attackers to inject arbitrary web script or HTML via the (1) item parameter in item.pl and (2) category parameter in itemlist.pl, which reflects the XSS in an error message. NOTE: the affected version might be wrong since the current version as of 20060116 is 3.6.1.

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.16% — more likely to be exploited than 82% of all CVEs
On CISA KEVno
Public exploityes
Published2006-01-16
Last modified2026-06-16

Affected (1)

VendorProduct
ultimate auctionultimate auction

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD