5.8
CVE-2006-1580
- EPSS 1.98%
- Veröffentlicht 02.04.2006 21:04:00
- Zuletzt bearbeitet 16.06.2026 22:23:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in Bugzero 4.3.1 and other versions allow remote attackers to inject arbitrary web script or HTML via the (1) msg parameter in query.jsp and (2) entryId parameter in edit.jsp.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.98% | 0.779 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://pridels0.blogspot.com/2006/04/bugzero-xss-vuln.html
http://secunia.com/advisories/19492
http://www.osvdb.org/24328
http://www.osvdb.org/24329
http://www.securityfocus.com/bid/17351
http://www.vupen.com/english/advisories/2006/1195
https://exchange.xforce.ibmcloud.com/vulnerabilities/25601