CVE-2006-6040: XSS
Multiple cross-site scripting (XSS) vulnerabilities in admincp/index.php in Jelsoft vBulletin 3.6.x allow remote attackers to inject arbitrary web script or HTML via (1) the prefs parameter in a buildnavprefs action or (2) the navprefs parameter in a savenavprefs action.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-6040?
CVE-2006-6040 has a medium severity rating due to its potential for cross-site scripting attacks.
How do I fix CVE-2006-6040?
To fix CVE-2006-6040, upgrade vBulletin to the latest version that addresses the XSS vulnerabilities.
What versions of vBulletin are affected by CVE-2006-6040?
CVE-2006-6040 affects vBulletin versions 3.6.0, 3.6.1, 3.6.2, and 3.6.3.
What is the impact of CVE-2006-6040?
The impact of CVE-2006-6040 allows an attacker to inject arbitrary scripts into web pages viewed by users.
How can I detect if my site is vulnerable to CVE-2006-6040?
You can detect CVE-2006-6040 vulnerabilities by reviewing user input handling in the admincp/index.php file.