6.8
CVE-2006-2491
- EPSS 2.75%
- Veröffentlicht 19.05.2006 23:02:00
- Zuletzt bearbeitet 16.06.2026 22:25:09
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in (1) index.php and (2) bmc/admin.php in BoastMachine (bMachine) 3.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the query string, which is not properly filtered when it is accessed using the $_SERVER["PHP_SELF"] variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Boastmachine ≫ Boastmachine Version <= 3.1
Boastmachine ≫ Boastmachine Version3.0 Editionplatinum
Kailash Nadh ≫ Boastmachine Version2.5
Kailash Nadh ≫ Boastmachine Version2.7
Kailash Nadh ≫ Boastmachine Version2.8
Kailash Nadh ≫ Boastmachine Version2.9b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.75% | 0.843 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20149
http://securityreason.com/securityalert/725
http://securityreason.com/securityalert/927
http://www.osvdb.org/25617
http://www.osvdb.org/25618
http://www.securityfocus.com/archive/1/434294/100/0/threaded
http://www.securityfocus.com/bid/18012
http://www.vupen.com/english/advisories/2006/1853
https://exchange.xforce.ibmcloud.com/vulnerabilities/26518