CVE detail
CVE-2006-0735 — CVE-2006-0735
Published 2006-02-16 · Modified 2026-06-16 · Vendor fuzzymonkey · Product my_blog · Source nvd
UNKNOWN
severity
CVSS-derived band
0.0289
EPSS probability
exploitation probability, 30d
86.0%
EPSS percentile
percentile vs all CVEs
NOT LISTED
CISA KEV
known exploited catalog
Description
Cross-site scripting (XSS) vulnerability in BBcode.pm in M. Blom HTML::BBCode 1.04 and earlier, as used in products such as My Blog before 1.65, allows remote attackers to inject arbitrary Javascript via a javascript URI in an (1) img or (2) url BBcode tag.
Remediation
No vendor-published fix data in our corpus for this CVE. Check the references below or the vendor's PSIRT / security advisories page.
References