CVE-2006-2986 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 3.9% (pctl 90)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in Baby Katie Media (a) very Simple Car Lister (vSCAL) 1.0 and (b) very simple Realty Lister (vsREAL) 1.0 allow remote attackers to inject arbitrary web script or HTML via the (1) lid parameter in index.php and the (2) title parameter in myslideshow.php.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 3.89% — more likely to be exploited than 90% of all CVEs |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-06-13 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| baby katie media | very simple car lister |
| baby katie media | very simple realty lister |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Baby Katie Media VSReal and VScal 1.0 - 'index.php?lid' Cross-Site Scripting | 2006-06-09 |
| exploit-db | Baby Katie Media VSReal and VScal 1.0 - 'myslideshow.php?title' Cross-Site Scripting | 2006-06-09 |
References
- http://secunia.com/advisories/20533
- http://securityreason.com/securityalert/1084
- http://www.securityfocus.com/archive/1/436411/100/0/threaded
- http://www.securityfocus.com/bid/18350
- http://www.vupen.com/english/advisories/2006/2238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27095
- http://secunia.com/advisories/20533
- http://securityreason.com/securityalert/1084
- http://www.securityfocus.com/archive/1/436411/100/0/threaded
- http://www.securityfocus.com/bid/18350
- http://www.vupen.com/english/advisories/2006/2238
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27095
→ the Explorer · watch your stack · NVD