2.6
CVE-2006-3245
- EPSS 1.73%
- Veröffentlicht 27.06.2006 10:05:00
- Zuletzt bearbeitet 16.06.2026 22:26:41
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in activatemember in mvnForum 1.0 GA and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) member and (2) activatecode parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.73% | 0.747 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 2.6 | 4.9 | 2.9 |
AV:N/AC:H/Au:N/C:N/I:P/A:N
|
http://pridels0.blogspot.com/2006/06/mvnforum-xss-vuln.html
http://secunia.com/advisories/20803
http://www.securityfocus.com/bid/18663
http://www.vupen.com/english/advisories/2006/2531
https://exchange.xforce.ibmcloud.com/vulnerabilities/27370