5.8

CVE-2006-3328

new_ticket.cgi in Hostflow 2.2.1-15 allows remote attackers to steal and replay authentication credentials via an IMG tag in the desc parameter ("Ticket Description" field) that points to a URL that captures referer URLs, possibly due to a cross-site scripting (XSS) vulnerability or a leak of credentials in referer URLs.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Starflow SoftwareHostflow Version2.2.1.15
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.32% 0.672
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.8 8.6 4.9
AV:N/AC:M/Au:N/C:P/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://pridels0.blogspot.com/2006/06/hostflow-vuln.html
http://secunia.com/advisories/20863
Vendor Advisory
http://www.osvdb.org/26872
http://www.securityfocus.com/bid/18695
http://www.vupen.com/english/advisories/2006/2570
https://exchange.xforce.ibmcloud.com/vulnerabilities/27426