Unrated severityNVD Advisory· Published Feb 23, 2006· Updated Apr 16, 2026
CVE-2006-0860
CVE-2006-0860
Description
Multiple cross-site scripting (XSS) vulnerabilities in Michael Salzer Guestbox 0.6, and other versions before 0.8, allow remote attackers to inject arbitrary web script or HTML via (1) HTML tags that follow a "http://" string, which bypasses a regular expression check, and (2) other unspecified attack vectors.
Affected products
1- cpe:2.3:a:michael_salzer:guestbox:0.6:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
7- secunia.com/advisories/18946nvdPatchVendor Advisory
- www.securityfocus.com/bid/16751nvdPatch
- www.vupen.com/english/advisories/2006/0675nvdVendor Advisory
- www.osvdb.org/23375nvd
- www.securityfocus.com/archive/1/425495/100/0/threadednvd
- www.securityfocus.com/archive/1/426663/100/0/threadednvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24798nvd
News mentions
0No linked articles in our index yet.