CVE-2006-5626
published 2006-10-31CVE-2006-5626: Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows…
PriorityP416medium4.3CVSS 2.0
AVNACMAuNCNIPAN
EXPLOIT
EPSS
1.93%
77.5th percentile
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| phpfaber | phpfaber_content_management_system | <= 1.3.36 | — |
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
phpFaber phpFaber Content Management System up to 1.3.35 vigilon cross site scripting (BID-20821 / SA22629)
vuldb·2026-04-26·CVSS 4.3
CVE-2006-5626 [MEDIUM] phpFaber phpFaber Content Management System up to 1.3.35 vigilon cross site scripting (BID-20821 / SA22629)
A vulnerability was found in phpFaber phpFaber Content Management System up to 1.3.35. It has been rated as problematic. This vulnerability affects unknown code. The manipulation of the argument vigilon leads to basic cross site scripting.
This vulnerability is uniquely identified as CVE-2006-5626. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
GHSA
GHSA-pp4w-rrm7-rp43: Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea
ghsa_unreviewed·2022-05-01
CVE-2006-5626 [MEDIUM] GHSA-pp4w-rrm7-rp43: Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea
Cross-site scripting (XSS) vulnerability in cms_images/js/htmlarea/htmlarea.php in phpFaber Content Management System (CMS) before 1.3.36 on 20061026 allows remote attackers to inject arbitrary web script or HTML, probably via arbitrary parameters in the query string, as demonstrated with a vigilon parameter. NOTE: earlier downloads of 1.3.36 have the vulnerability; the software was updated without changing the version number.
No detection rules found.
No writeups or analysis indexed.
http://secunia.com/advisories/22629http://securityreason.com/securityalert/1802http://www.securityfocus.com/archive/1/449894/100/0/threadedhttp://www.securityfocus.com/bid/20821http://www.vigilon.com/advisories/vg-phpfaber-24-10-2006.txthttp://www.vigilon.com/resources/102506c.htmlhttp://www.vupen.com/english/advisories/2006/4260http://secunia.com/advisories/22629http://securityreason.com/securityalert/1802http://www.securityfocus.com/archive/1/449894/100/0/threadedhttp://www.securityfocus.com/bid/20821http://www.vigilon.com/advisories/vg-phpfaber-24-10-2006.txthttp://www.vigilon.com/resources/102506c.htmlhttp://www.vupen.com/english/advisories/2006/4260
2006-10-31
Published