4.3
CVE-2006-1971
- EPSS 2.09%
- Veröffentlicht 21.04.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:02
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in login.php in KRANKIKOM ContentBoxX allows remote attackers to inject arbitrary web script or HTML via the action parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.09% | 0.792 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/19733
http://securityreason.com/securityalert/740
http://securityreason.com/securityalert/779
http://www.osvdb.org/24768
http://www.securityfocus.com/archive/1/431386/100/0/threaded
http://www.securityfocus.com/bid/17612
http://www.vupen.com/english/advisories/2006/1438
https://exchange.xforce.ibmcloud.com/vulnerabilities/25952