Unrated severityNVD Advisory· Published Jun 28, 2006· Updated Apr 16, 2026
CVE-2006-3278
CVE-2006-3278
Description
Cross-site scripting (XSS) vulnerability in H-Sphere 2.5.1 Beta 1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) next_template, (2) start, (3) curr_menu_id, and (4) arid parameters in psoft/servlet/resadmin/psoft.hsphere.CP when using the mailman/massmail.html template_name.
Affected products
5cpe:2.3:a:positive_software:h-sphere:*:*:*:*:*:*:*:*+ 4 more
- cpe:2.3:a:positive_software:h-sphere:*:*:*:*:*:*:*:*range: <=2.5.1_beta_1
- cpe:2.3:a:positive_software:h-sphere:2.5:*:*:*:*:*:*:*
- cpe:2.3:a:positive_software:h-sphere:2.5_patch_1:*:*:*:*:*:*:*
- cpe:2.3:a:positive_software:h-sphere:2.5_patch_2:*:*:*:*:*:*:*
- cpe:2.3:a:positive_software:h-sphere:2.5_rc_3:*:*:*:*:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
6News mentions
0No linked articles in our index yet.