4.3

CVE-2006-2851

Exploit
Cross-site scripting (XSS) vulnerability in index.php in dotProject 2.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, which are not properly handled when the client is using Internet Explorer.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
DotprojectDotproject Version2.0
DotprojectDotproject Version2.0.1
DotprojectDotproject Version2.0.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.34% 0.676
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://jvn.jp/jp/JVN%2397636431/index.html
http://secunia.com/advisories/20418
Vendor Advisory
Exploit
http://sourceforge.net/project/shownotes.php?release_id=422371
Patch
http://www.securityfocus.com/bid/18275
http://www.vupen.com/english/advisories/2006/2124
https://exchange.xforce.ibmcloud.com/vulnerabilities/26904