← Vulnerability feed

Vulnerability record · CVE-2006-6687 · published 21 December 2006

CVE-2006-6687: Web-app.net webapp cross-site scripting vulnerability

WWeb App.Net · Webapp

Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

4.3 CVSS 2.0 Medium EPSS 0.93% · top 40.8% CWE-79 · Cross-site scripting
4.3CVSS 2.0 base score
0.93%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: The provenance of this information is unknown; the details are obtained solely from third party information.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6687 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-3242Web-app.net webapp permissions and access controls vulnerabilityThe Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote a…EPSS 2.1%7.5CVE-2007-1829Web-app.net webapp vulnerabilityMultiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having] other [security] issues too…EPSS 0.99%7.5CVE-2006-6688Web-app.net webapp vulnerabilityWeb Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanism…EPSS 1.4%5.0CVE-2006-7186Web-app.net webapp vulnerabilitycgi-lib/subs.pl in web-app.net WebAPP before 0.9.9.3.5 allows attackers to open list files in "profile and other functions," a different vulnerabilit…EPSS 1.0%5.0CVE-2006-7188Web-app.net webapp vulnerabilityThe search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via cert…EPSS 1.1%4.3CVE-2006-7187Web-app.net webapp vulnerabilityCross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 all…EPSS 0.85%4.3CVE-2006-7189Web-app.net webapp vulnerabilityCross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary …EPSS 0.85%4.3CVE-2006-7190Web-app.net webapp vulnerabilityCross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitr…EPSS 0.85%

Source: NIST National Vulnerability Database (record CVE-2006-6687), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.