Unrated severityNVD Advisory· Published Feb 25, 2006· Updated Apr 16, 2026
CVE-2006-0894
CVE-2006-0894
Description
Multiple cross-site scripting (XSS) vulnerabilities in NOCC Webmail 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the html_error_occurred parameter in error.php, (2) html_filter_select parameter in filter_prefs.php, (3) html_no_mail parameter in no_mail.php, the (4) page_line, (5) prev, and (6) next parameters in html_bottom_table.php, and the (7) _SESSION['nocc_theme'] parameter in footer.php.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
10- archives.neohapsis.com/archives/bugtraq/2006-02/0418.htmlnvdExploit
- secunia.com/advisories/16921nvdVendor Advisory
- retrogod.altervista.org/noccw_10_incl_xpl.htmlnvd
- securitytracker.com/idnvd
- www.osvdb.org/23423nvd
- www.osvdb.org/23424nvd
- www.osvdb.org/23425nvd
- www.osvdb.org/23426nvd
- www.osvdb.org/23427nvd
- www.securityfocus.com/bid/16793nvd
News mentions
0No linked articles in our index yet.