Unrated severityNVD Advisory· Published Mar 7, 2006· Updated Apr 16, 2026
CVE-2006-1040
CVE-2006-1040
Description
Cross-site scripting (XSS) vulnerability in vBulletin 3.0.12 and 3.5.3 allows remote attackers to inject arbitrary web script or HTML via the email field, which is injected in profile.php but not sanitized in sendmsg.php.
Affected products
2Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- www.kapda.ir/advisory-266.htmlnvdExploitPatchVendor Advisory
- secunia.com/advisories/19100nvd
- www.osvdb.org/23614nvd
- www.securityfocus.com/archive/1/426537/100/0/threadednvd
- www.securityfocus.com/archive/1/426589/100/0/threadednvd
- www.securityfocus.com/bid/16919nvd
- www.vbulletin.com/forum/showthread.phpnvd
- www.vupen.com/english/advisories/2006/0808nvd
News mentions
0No linked articles in our index yet.