CVE-2006-3333
Status: ModifiedLow (2.6)—
Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection.
CVSS
- Version: 2.0
- Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N
- Base score: 2.6
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 0.83%
- Percentile among all scored CVEs: 56
- Score date: 10/5/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (1)
CWEs
- NVD-CWE-Other
References
Raw JSON (NVD)
Show
{
"id": "CVE-2006-3333",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 2.6,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:H/Au:N/C:N/I:P/A:N",
"authentication": "NONE",
"integrityImpact": "PARTIAL",
"accessComplexity": "HIGH",
"availabilityImpact": "NONE",
"confidentialityImpact": "NONE"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "LOW",
"obtainAllPrivilege": false,
"exploitabilityScore": 4.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": true
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2006-06-30T23:05:00.000",
"references": [
{
"url": "http://pridels0.blogspot.com/2006/06/zorum-forum-35-vuln.html",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/19598",
"source": "cve@mitre.org"
},
{
"url": "http://pridels0.blogspot.com/2006/06/zorum-forum-35-vuln.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/19598",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-Other"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Cross-site scripting (XSS) vulnerability in index.php in Zorum Forum 3.5 allows remote attackers to inject web script or HTML via the multiple unspecified parameters, including the (1) frommethod, (2) list, and (3) method, which are reflected in an error message. NOTE: some of these vectors might be resultant from SQL injection."
},
{
"lang": "es",
"value": "Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en index.php en Zorum Forum v3.5 permite a los atacantes remotos inyectar una secuencia de comandos web o HTML a través de parámetro múltiples no especificados, incluyendo (1) frommethod, (2) list, y (3) method, que son reflejados en un mensaje de error. NOTA: algunos de estos vectores deben ser el resultado de una inyección SQL."
}
],
"lastModified": "2026-06-16T22:26:51.723",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:phpoutsourcing:zorum:3.5:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "D7D1D438-86A5-4224-852F-EC1E5DB83DC4"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}