Unrated severityNVD Advisory· Published Jan 13, 2006· Updated Apr 16, 2026
CVE-2006-0204
CVE-2006-0204
Description
Multiple cross-site scripting (XSS) vulnerabilities in Wordcircle 2.17 allow remote attackers to inject arbitrary web script or HTML via (1) the "Course name" field in index.php when the frm parameter has the value "mine" and (2) possibly certain other fields in unspecified scripts.
Affected products
1- cpe:2.3:a:wordcircle:wordcircle:2.17:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- evuln.com/vulns/28/summary.htmlnvdExploitVendor Advisory
- www.osvdb.org/22359nvdExploit
- secunia.com/advisories/18440nvdVendor Advisory
- securityreason.com/securityalert/345nvd
- www.securityfocus.com/archive/1/421746/100/0/threadednvd
- www.securityfocus.com/bid/16227nvd
- www.vupen.com/english/advisories/2006/0185nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24106nvd
News mentions
0No linked articles in our index yet.