CVE-2006-3183
Status: ModifiedMedium (6.8)—
Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when (2) updating a profile, (3) posting comments or entries in a blog, (4) uploading files, (5) picture captions, and (6) sending a private message (PM).
CVSS
- Version: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P
- Base score: 6.8
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.44%
- Percentile among all scored CVEs: 72
- Score date: 10/3/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
- http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html
- http://secunia.com/advisories/20611
- http://securityreason.com/securityalert/1128
- http://www.osvdb.org/26419
- http://www.vupen.com/english/advisories/2006/2312
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27151
- http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html
- http://secunia.com/advisories/20611
- http://securityreason.com/securityalert/1128
- http://www.osvdb.org/26419
- http://www.vupen.com/english/advisories/2006/2312
- https://exchange.xforce.ibmcloud.com/vulnerabilities/27151
Raw JSON (NVD)
Show
{
"id": "CVE-2006-3183",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 6.8,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "MEDIUM",
"availabilityImpact": "PARTIAL",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 6.4,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": true,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-06-23T00:02:00.000",
"references": [
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/20611",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://securityreason.com/securityalert/1128",
"source": "cve@mitre.org"
},
{
"url": "http://www.osvdb.org/26419",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2312",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27151",
"source": "cve@mitre.org"
},
{
"url": "http://archives.neohapsis.com/archives/bugtraq/2006-06/0115.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/20611",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/1128",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.osvdb.org/26419",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2006/2312",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27151",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in index.php in MobeScripts Mobile Space Community 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) browse parameter, which is not filtered in the resulting error message, and multiple unspecified input fields, including those involved when (2) updating a profile, (3) posting comments or entries in a blog, (4) uploading files, (5) picture captions, and (6) sending a private message (PM)."
},
{
"lang": "es",
"value": "Vulnerabilidades de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en MobeScripts Mobile Space Community v2.0 y anteriores, permite a atacantes remotos inyectar secuencias de comandos web o HTML a través del parámetro a (1)mostrar parámetros, que no se filtra en el error resultante y múltiples campos de entrada cuando(2)se actualiza un perfil,(3)se introducen comentarios o entradas en un blog,(4) se suben ficheros, (5) se toman fotos y (6) enviando mensajes privados .\r\n"
}
],
"lastModified": "2026-06-16T22:26:33.780",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:mobescripts:mobile_space_community:2.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2A241A9-6882-4F81-89CA-183B5A874370"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}