4.3
CVE-2006-1222
- EPSS 1.76%
- Veröffentlicht 14.03.2006 11:02:00
- Zuletzt bearbeitet 16.06.2026 22:22:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.76% | 0.751 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042872.html
http://secunia.com/advisories/19214
http://www.inetcop.org/upfiles/33INCSA.2006-0x82-029-zeroboard.pdf
http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&no=5406
http://www.osvdb.org/23847
http://www.securityfocus.com/archive/1/427466/100/0/threaded
http://www.securityfocus.com/bid/17075
http://www.vupen.com/english/advisories/2006/0944
https://exchange.xforce.ibmcloud.com/vulnerabilities/25212