4.3
CVE-2006-3514
- EPSS 1.28%
- Veröffentlicht 11.07.2006 23:05:00
- Zuletzt bearbeitet 16.06.2026 22:27:13
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in admin/actions.php in PHP-Blogger 2.2.5, and possibly earlier versions, allow remote attackers to execute arbitrary web script or HTML via the (1) name, (2) title, (3) news, (4) description, and (5) sitename parameters.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Phpblogger ≫ Php-blogger Version2.2.5
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.28% | 0.661 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://secunia.com/advisories/20989
http://securityreason.com/securityalert/1202
http://www.securityfocus.com/archive/1/439440/100/0/threaded
http://www.securityfocus.com/bid/18909
http://www.vupen.com/english/advisories/2006/2710
https://exchange.xforce.ibmcloud.com/vulnerabilities/27630