CVE-2006-2746 EXPLOIT
6.8
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao. NOTE: vectors 2 and 3 might be resultant from file inclusion issues.
Scoring
| CVSS | 6.8 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
| EPSS | 3.09% — more likely to be exploited than 87% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-01 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| facile interactive web | facile interactive web |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | F@cile Interactive Web 0.8x - Remote File Inclusion / Cross-Site Scripting | 2006-05-28 |
References
- http://secunia.com/advisories/20358
- http://securityreason.com/securityalert/1010
- http://www.nukedx.com/?getxpl=35
- http://www.nukedx.com/?viewdoc=35
- http://www.osvdb.org/26104
- http://www.osvdb.org/26105
- http://www.securityfocus.com/archive/1/435283/100/0/threaded
- http://www.securityfocus.com/bid/18151
- http://www.vupen.com/english/advisories/2006/2036
- http://secunia.com/advisories/20358
- http://securityreason.com/securityalert/1010
- http://www.nukedx.com/?getxpl=35
- http://www.nukedx.com/?viewdoc=35
- http://www.osvdb.org/26104
- http://www.osvdb.org/26105
- http://www.securityfocus.com/archive/1/435283/100/0/threaded
- http://www.securityfocus.com/bid/18151
- http://www.vupen.com/english/advisories/2006/2036
→ the Explorer · watch your stack · NVD