Loading...
Loading...
Multiple cross-site scripting (XSS) vulnerabilities in index.php in NewsPHP 2006 PRO allow remote attackers to inject arbitrary web script or HTML via the (1) words, (2) id, (3) cat_id, and (4) tim parameters, which are not sanitized before being returned in an error page. NOTE: it is possible that some of these vectors are resultant from an SQL injection issue.
July 6, 2006
April 16, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-3358
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.