peter bassill · operator
$ cve CVE-2006-2109 JSON

CVE-2006-2109 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 2.3% (pctl 83)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in the parse_query_str function in include/print.php in JSBoard 2.0.10 and 2.0.11, and possibly other versions before 2.0.12, allows remote attackers to inject arbitrary web script or HTML via parameters that are set as global variables within the program, as demonstrated using the table parameter to login.php.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS2.29% — more likely to be exploited than 83% of all CVEs
On CISA KEVno
Public exploityes
Published2006-05-02
Last modified2026-06-16

Affected (1)

VendorProduct
jsboardjsboard

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD