5.8
CVE-2006-3036
- EPSS 4.27%
- Veröffentlicht 15.06.2006 10:02:00
- Zuletzt bearbeitet 16.06.2026 22:26:16
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in 35mmslidegallery 6.0 allow remote attackers to inject arbitrary web script or HTML via the (1) imgdir parameter in (a) index.php, and the (2) w, (3) h, and (4) t parameters in (b) popup.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Andy Mack ≫ 35mmslidegallery Version6.0
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 4.27% | 0.898 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.8 | 8.6 | 4.9 |
AV:N/AC:M/Au:N/C:P/I:P/A:N
|
http://secunia.com/advisories/20652
http://securityreason.com/securityalert/1100
http://www.osvdb.org/26507
http://www.osvdb.org/26508
http://www.securityfocus.com/archive/1/436959/100/0/threaded
http://www.securityfocus.com/bid/18414
https://exchange.xforce.ibmcloud.com/vulnerabilities/27127