6.8
CVE-2006-1661
- EPSS 2.43%
- Veröffentlicht 07.04.2006 10:04:00
- Zuletzt bearbeitet 16.06.2026 22:23:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in SKForum 1.5 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) areaID parameter in area.View.action, (2) time parameter in planning.View.action, and (3) userID parameter in user.View.action.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.43% | 0.821 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://pridels0.blogspot.com/2006/04/skforum-xss-vuln.html
http://secunia.com/advisories/19484
http://www.osvdb.org/24430
http://www.osvdb.org/24431
http://www.osvdb.org/24432
http://www.securityfocus.com/bid/17389
http://www.vupen.com/english/advisories/2006/1260
https://exchange.xforce.ibmcloud.com/vulnerabilities/25641