4.9
CVE-2006-2477
- EPSS 1.15%
- Veröffentlicht 19.05.2006 17:02:00
- Zuletzt bearbeitet 16.06.2026 22:25:05
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in the administrative interface Bitrix Site Manager 4.1.x allows remote attackers to inject arbitrary web script or HTML via unspecified inputs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Bitrix ≫ Bitrix Site Manager Version4.0.0
Bitrix ≫ Bitrix Site Manager Version4.0.2
Bitrix ≫ Bitrix Site Manager Version4.0.3
Bitrix ≫ Bitrix Site Manager Version4.0.4
Bitrix ≫ Bitrix Site Manager Version4.0.5
Bitrix ≫ Bitrix Site Manager Version4.0.6
Bitrix ≫ Bitrix Site Manager Version4.0.7
Bitrix ≫ Bitrix Site Manager Version4.0.8
Bitrix ≫ Bitrix Site Manager Version4.1.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.15% | 0.627 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.9 | 6.8 | 4.9 |
AV:N/AC:M/Au:S/C:P/I:P/A:N
|
http://secunia.com/advisories/20143
http://securityreason.com/securityalert/918
http://securitytracker.com/id?1016121
http://www.securityfocus.com/archive/1/434367/100/0/threaded
http://www.vupen.com/english/advisories/2006/1858
https://exchange.xforce.ibmcloud.com/vulnerabilities/26544