4.3

CVE-2006-1222

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in zeroboard 4.1 pl7 allows allow remote attackers to inject arbitrary web script or HTML via the (1) memo box title, (2) user email, and (3) homepage fields.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ZeroboardZeroboard Version4.1_pl2
ZeroboardZeroboard Version4.1_pl3
ZeroboardZeroboard Version4.1_pl4
ZeroboardZeroboard Version4.1_pl5
ZeroboardZeroboard Version4.1_pl6
ZeroboardZeroboard Version4.1_pl7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.76% 0.751
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.grok.org.uk/pipermail/full-disclosure/2006-March/042872.html
Patch
Vendor Advisory
Exploit
http://secunia.com/advisories/19214
Patch
Vendor Advisory
http://www.inetcop.org/upfiles/33INCSA.2006-0x82-029-zeroboard.pdf
Vendor Advisory
http://www.nzeo.com/bbs/zboard.php?id=cgi_bugreport2&no=5406
http://www.osvdb.org/23847
http://www.securityfocus.com/archive/1/427466/100/0/threaded
http://www.securityfocus.com/bid/17075
Patch
http://www.vupen.com/english/advisories/2006/0944
https://exchange.xforce.ibmcloud.com/vulnerabilities/25212