cbcvebase.
CVE-2006-0735
published 2006-02-16

CVE-2006-0735: Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote…

PriorityP418medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
2.83%
84.8th percentile
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.

Affected

18 ranges
VendorProductVersion rangeFixed in
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
fuzzymonkeymy_blog
m_blomhtml-bbcode
m_blomhtml-bbcode
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.