2.6

CVE-2006-3848

Cross-site scripting (XSS) vulnerability in CGI wrapper for IP Calculator (IPCalc) 0.40 allows remote attackers to inject arbitrary web script or HTML via the URI (REQUEST_URI environment variable), which is used in the actionurl variable.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Krischan JodiesIp Calculator Version0.40
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.67% 0.738
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 2.6 4.9 2.9
AV:N/AC:H/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0487.html
http://archives.neohapsis.com/archives/fulldisclosure/2006-07/att-0487/NDSA20060705.txt.asc
http://secunia.com/advisories/21151
Vendor Advisory
http://www.osvdb.org/27446
http://www.securityfocus.com/archive/1/440860/100/100/threaded
http://www.securityfocus.com/archive/1/441304/100/0/threaded
http://www.securityfocus.com/bid/19130
http://www.vupen.com/english/advisories/2006/2944
https://exchange.xforce.ibmcloud.com/vulnerabilities/27924