Loading...
Loading...
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.
October 31, 2006
April 23, 2026
See which npm, PyPI, Go, and Maven packages are affected by CVE-2006-5626
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.