2.6

CVE-2006-2311

Exploit
Cross-site scripting (XSS) vulnerability in BlueDragon Server and Server JX 6.2.1.286 for Windows allows remote attackers to inject arbitrary web script or HTML via the filename in a request to a (1) .cfm or (2) .cfml file, which reflects the result in the default error page.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
New Atlanta CommunicationsBluedragon Server Version6.2.1.286 Editionwindows
New Atlanta CommunicationsBluedragon Server Jx Version6.2.1.286 Editionwindows
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/19180
Vendor Advisory
Exploit
http://secunia.com/secunia_research/2006-18/advisory
Vendor Advisory
Exploit
http://www.vupen.com/english/advisories/2006/2502
http://www.securityfocus.com/bid/18623