4.3

CVE-2006-2227

Cross-site scripting (XSS) vulnerability in misc.php in PunBB 1.2.11 allows remote attackers to inject arbitrary web script or HTML via the req_message parameter, because the value of the redirect_url parameter is not sanitized.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PunbbPunbb Version1.2.11
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.68% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19986
Vendor Advisory
http://securityreason.com/securityalert/849
http://www.osvdb.org/25256
http://www.punbb.org/changelogs/1.2.11_to_1.2.12.txt
http://www.punbb.org/download/hdiff/hdiff-1.2.11_to_1.2.12.html
http://www.securityfocus.com/archive/1/432950/100/0/threaded
http://www.securityfocus.com/bid/17827
http://www.vupen.com/english/advisories/2006/1670
https://exchange.xforce.ibmcloud.com/vulnerabilities/26245