2.6
CVE-2006-1144
- EPSS 5.05%
- Veröffentlicht 10.03.2006 11:02:00
- Zuletzt bearbeitet 16.06.2026 22:22:06
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in HitHost 1.0.0 allows remote attackers to inject arbitrary web script or HTML via (1) the user parameter in deleteuser.php and (2) the hits parameter in viewuser.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
David Ravenscroft ≫ Hithost Version1.0.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.05% | 0.912 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/19155
http://www.osvdb.org/23757
http://www.osvdb.org/23758
http://www.securityfocus.com/archive/1/426931/100/0/threaded
http://www.securityfocus.com/bid/17025
http://www.vupen.com/english/advisories/2006/0886
https://exchange.xforce.ibmcloud.com/vulnerabilities/25105