Unrated severityNVD Advisory· Published Feb 8, 2006· Updated Jun 16, 2026
CVE-2006-0593
CVE-2006-0593
Description
Cross-site scripting (XSS) vulnerability in PHP-Fusion before 6.00.304 allows remote attackers to inject arbitrary web script or HTML via the (1) shout_name field in shoutbox_panel.php and the (2) comments field in comments_include.php.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
19cpe:2.3:a:php_fusion:php_fusion:6.00.100:*:*:*:*:*:*:*+ 18 more
- cpe:2.3:a:php_fusion:php_fusion:6.00.100:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.101:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.102:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.103:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.104:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.105:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.106:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.107:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.108:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.109:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.110:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.200:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.204:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.205:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.206:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.207:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.300:*:*:*:*:*:*:*
- cpe:2.3:a:php_fusion:php_fusion:6.00.303:*:*:*:*:*:*:*
- (no CPE)range: <6.00.304
Patches
Vulnerability mechanics
References
8News mentions
0No linked articles in our index yet.