4.3

CVE-2006-2553

Cross-site scripting (XSS) vulnerability in Jemscripts DownloadControl 1.0 allows remote attackers to inject arbitrary HTML or web script via the dcid parameter to dc.php.  NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. This issue appears to be independent from a different issue that involves the same vector.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
JemscriptsDownloadcontrol Version1.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.37% 0.683
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://securityreason.com/securityalert/943
http://www.securityfocus.com/archive/1/434533/100/0/threaded
http://www.vupen.com/english/advisories/2006/1928
http://secunia.com/advisories/20212
Vendor Advisory
http://www.attrition.org/pipermail/vim/2006-May/000783.html
http://www.osvdb.org/25715
https://exchange.xforce.ibmcloud.com/vulnerabilities/26624