Unrated severityNVD Advisory· Published Feb 28, 2006· Updated Apr 16, 2026
CVE-2006-0923
CVE-2006-0923
Description
Multiple cross-site scripting (XSS) vulnerabilities in MyPHPNuke (MPN) 1.88 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the letter parameter in reviews.php and (2) the dcategory parameter in download.php.
Affected products
3Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.nukedx.comnvdExploitVendor Advisory
- secunia.com/advisories/19052nvd
- securityreason.com/securityalert/491nvd
- www.myphpnuke.com/article.phpnvd
- www.securityfocus.com/archive/1/425983/100/0/threadednvd
- www.securityfocus.com/bid/16815nvd
- www.vupen.com/english/advisories/2006/0750nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/24887nvd
News mentions
0No linked articles in our index yet.