peter bassill · operator
$ cve CVE-2006-2746 JSON

CVE-2006-2746 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 3.1% (pctl 87)

Patch early

A public exploit exists.

Description

Multiple cross-site scripting (XSS) vulnerabilities in F@cile Interactive Web 0.8.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) lang parameter in index.php, and the (2) mytheme and (3) myskin parameters in multiple "p-themes" index.inc.php files including (c) lowgraphic, (d) classic, (e) puzzle, (f) simple, and (g) ciao. NOTE: vectors 2 and 3 might be resultant from file inclusion issues.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS3.09% — more likely to be exploited than 87% of all CVEs
On CISA KEVno
Public exploityes
Published2006-06-01
Last modified2026-06-16

Affected (1)

VendorProduct
facile interactive webfacile interactive web

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD