4.3

CVE-2006-2637

Cross-site scripting (XSS) vulnerability in view.php in TuttoPhp (1) Morris Guestbook 1, (2) Pretty Guestbook 1, and (3) Smile Guestbook 1 allows remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the pagina parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.92% 0.773
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/20320
Vendor Advisory
http://secunia.com/advisories/20321
Vendor Advisory
http://secunia.com/advisories/20322
Vendor Advisory
http://securityreason.com/securityalert/973
http://www.securityfocus.com/archive/1/435171/100/0/threaded
http://www.securityfocus.com/archive/1/435172/100/0/threaded
http://www.securityfocus.com/archive/1/435173/100/0/threaded
http://www.securityfocus.com/bid/18128
http://www.vupen.com/english/advisories/2006/2016
http://www.vupen.com/english/advisories/2006/2017
http://www.vupen.com/english/advisories/2006/2018
https://exchange.xforce.ibmcloud.com/vulnerabilities/26731
https://exchange.xforce.ibmcloud.com/vulnerabilities/26734
https://exchange.xforce.ibmcloud.com/vulnerabilities/26735