4.3

CVE-2006-2167

Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SloughflashSf-users Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.3% 0.667
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19932
Vendor Advisory
http://securityreason.com/securityalert/831
http://www.securityfocus.com/archive/1/432727/100/0/threaded
http://www.securityfocus.com/bid/17783
http://www.vupen.com/english/advisories/2006/1637
https://exchange.xforce.ibmcloud.com/vulnerabilities/26215