peter bassill · operator
$ cve CVE-2006-4796 JSON

CVE-2006-4796 EXPLOIT

4.3
MEDIUM · CVSS 2.0 · EPSS 2.5% (pctl 84)

Patch early

A public exploit exists.

Description

Cross-site scripting (XSS) vulnerability in forum.asp in Snitz Forums 2000 3.4.06 allows remote attackers to inject arbitrary web script or HTML via the sortorder parameter (strtopicsortord variable).

Scoring

CVSS4.3 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:N/I:P/A:N
EPSS2.46% — more likely to be exploited than 84% of all CVEs
On CISA KEVno
Public exploityes
Published2006-09-14
Last modified2026-06-16

Affected (1)

VendorProduct
snitz communicationssnitz forums 2000

Public exploits

SourceTitleDate
exploit-dbSnitz Forums 2000 - 'forum.asp' Cross-Site Scripting2006-09-13

References

→ the Explorer  ·  watch your stack  ·  NVD