Loading
Cross-site scripting (XSS) vulnerability in the "Basic Toolbar Selection" in FCKEditor allows remote attackers to execute arbitrary JavaScript via the javascript: URI in the (1) href or (2) onmouseover attribute of the A HTML tag.
Cite this page
CVE-2006-6978. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2006-6978
Use CWE-79, Fckeditor vendor hub and Fckeditor product page to widen CVE-2006-6978 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2009-2265, CVE-2008-6178 and CVE-2006-0921 for nearby disclosures in the same product family.