← Vulnerability feed

Vulnerability record · CVE-2006-7190 · published 3 April 2007

CVE-2006-7190: Web-app.net webapp vulnerability

WWeb App.Net · Webapp

Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc.

4.3 CVSS 2.0 Medium EPSS 0.85% · top 43.7%
4.3CVSS 2.0 base score
0.85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Cross-site scripting (XSS) vulnerability in cgi-bin/user-lib/topics.pl in web-app.net WebAPP before 20060515 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors in the viewnews function, related to use of doubbctopic instead of doubbc.

AV:N/AC:M/Au:N/C:N/I:P/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-7190 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.5CVE-2007-3242Web-app.net webapp permissions and access controls vulnerabilityThe Menu Manager Mod for (1) web-app.net WebAPP (aka WebAPP NE) 0.9.9.3.3 through 0.9.9.8, and (2) web-app.org WebAPP before 0.9.9.6, allows remote a…EPSS 2.1%7.5CVE-2007-1829Web-app.net webapp vulnerabilityMultiple unspecified vulnerabilities in web-app.net WebAPP have unknown impact and attack vectors, described as "[having] other [security] issues too…EPSS 0.99%7.5CVE-2006-6688Web-app.net webapp vulnerabilityWeb Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET) allows remote attackers to bypass filtering mechanism…EPSS 1.4%5.0CVE-2006-7186Web-app.net webapp vulnerabilitycgi-lib/subs.pl in web-app.net WebAPP before 0.9.9.3.5 allows attackers to open list files in "profile and other functions," a different vulnerabilit…EPSS 1.0%5.0CVE-2006-7188Web-app.net webapp vulnerabilityThe search function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 allows remote attackers to read internal forum posts via cert…EPSS 1.1%4.3CVE-2006-7187Web-app.net webapp vulnerabilityCross-site scripting (XSS) vulnerability in the show_recent_searches function in cgi-lib/user-lib/search.pl in web-app.net WebAPP before 20060909 all…EPSS 0.85%4.3CVE-2006-7189Web-app.net webapp vulnerabilityCross-site scripting (XSS) vulnerability in cgi-bin/admin/logs.cgi in web-app.net WebAPP before 20060403 allows remote attackers to inject arbitrary …EPSS 0.85%4.3CVE-2006-6687Web-app.net webapp cross-site scripting vulnerabilityCross-site scripting (XSS) vulnerability in Web Automated Perl Portal (WebAPP) 0.9.9.4, and 0.9.9.3.4 Network Edition (NE) (aka WebAPP.NET), allows r…EPSS 0.93%

Source: NIST National Vulnerability Database (record CVE-2006-7190), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.