4.3

CVE-2006-3826

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in Kailash Nadh boastMachine (formerly bMachine) 3.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) user_login, (2) full_name, and (3) URL parameters in register.php; and allow remote authenticated administrators to inject arbitrary web script or HTML via the (4) cat_list and (5) key parameters in a certain portion of the admin interface.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Kailash NadhBoastmachine Version2.5
Kailash NadhBoastmachine Version2.7
Kailash NadhBoastmachine Version2.8
Kailash NadhBoastmachine Version2.9b
Kailash NadhBoastmachine Version3.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.36% 0.681
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/21066
Vendor Advisory
http://securityreason.com/securityalert/1252
http://securitytracker.com/id?1016515
http://www.acid-root.new.fr/advisories/boastmachine.txt
Exploit
http://www.securityfocus.com/archive/1/440306/100/0/threaded
http://www.vupen.com/english/advisories/2006/2849
https://exchange.xforce.ibmcloud.com/vulnerabilities/27771