4.3
CVE-2006-1233
- EPSS 2.46%
- Veröffentlicht 14.03.2006 19:06:00
- Zuletzt bearbeitet 16.06.2026 22:22:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in WMNews allow remote attackers to inject arbitrary web script or HTML via the (1) ArtCat parameter to wmview.php, (2) ctrrowcol parameter to footer.php, or (3) ArtID parameter to wmcomments.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.46% | 0.823 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://biyosecurity.be/bugs/wmnews.txt
http://secunia.com/advisories/19204
http://www.osvdb.org/23840
http://www.osvdb.org/23841
http://www.osvdb.org/23842
http://www.securityfocus.com/archive/1/427479/100/0/threaded
http://www.securityfocus.com/bid/17076
http://www.vupen.com/english/advisories/2006/0939
https://exchange.xforce.ibmcloud.com/vulnerabilities/25210