4.3
CVE-2006-3260
- EPSS 1.4%
- Veröffentlicht 27.06.2006 21:05:00
- Zuletzt bearbeitet 16.06.2026 22:26:43
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in index.php in vlbook 1.02 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Virtual Design Studios ≫ Vlbook Version1.0.2
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://colander.altervista.org/advisory/vlbook.txt
http://secunia.com/advisories/20776
http://securityreason.com/securityalert/1150
http://securitytracker.com/id?1016379
http://www.securityfocus.com/archive/1/438146/100/0/threaded
http://www.securityfocus.com/bid/18618
http://www.vupen.com/english/advisories/2006/2505
https://exchange.xforce.ibmcloud.com/vulnerabilities/27333