5.8
CVE-2006-2415
- EPSS 1.34%
- Veröffentlicht 16.05.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:24:57
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in FlexChat 2.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) username and (2) CFTOKEN parameter in (a) index.cfm and (3) CFTOKEN and (4) CFID parameter in (b) chat.cfm.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.34% | 0.677 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://pridels0.blogspot.com/2006/05/flexchat-xss.html
http://secunia.com/advisories/20101
http://securitytracker.com/id?1016104
http://www.osvdb.org/25504
http://www.osvdb.org/25505
http://www.vupen.com/english/advisories/2006/1804
https://exchange.xforce.ibmcloud.com/vulnerabilities/26429