6.8
CVE-2006-4079
- EPSS 1.25%
- Veröffentlicht 11.08.2006 01:04:00
- Zuletzt bearbeitet 16.06.2026 22:28:23
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in newpost.php in DeluxeBB 1.08, and possibly earlier, allows remote attackers to inject arbitrary web script or HTML via the subject parameter (aka the topic title field).
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.25% | 0.655 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://securityreason.com/securityalert/1381
http://www.securityfocus.com/archive/1/442464/100/0/threaded
http://www.osvdb.org/27833
http://www.securityfocus.com/bid/19390
https://exchange.xforce.ibmcloud.com/vulnerabilities/28272