4.3
CVE-2006-2167
- EPSS 1.3%
- Veröffentlicht 04.05.2006 12:38:00
- Zuletzt bearbeitet 16.06.2026 22:24:28
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in SloughFlash SF-Users 1.0, possibly in register.php, allows remote attackers to inject arbitrary web script or HTML by setting the username field to contain JavaScript in the SRC attribute of an IMG element.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Sloughflash ≫ Sf-users Version1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.3% | 0.667 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/19932
http://securityreason.com/securityalert/831
http://www.securityfocus.com/archive/1/432727/100/0/threaded
http://www.securityfocus.com/bid/17783
http://www.vupen.com/english/advisories/2006/1637
https://exchange.xforce.ibmcloud.com/vulnerabilities/26215