4.3

CVE-2006-4206

Cross-site scripting (XSS) vulnerability in calendar.asp in ASPPlayground.NET Forum Advanced Edition 2.4.5 Unicode, and possibly other versions before October 15, 2006, allows remote attackers to inject arbitrary web script or HTML via the calendarID parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Aspplayground.NetAspplayground.Net Version2.4.5 Editionadvanced_and_unicode
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.51% 0.827
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://nvd.nist.gov/nvd.cfm?cvename=CVE-2006-4206
US Government Resource
http://securityreason.com/securityalert/1405
http://www.osvdb.org/29232
http://www.securityfocus.com/archive/1/443035/100/0/threaded
http://www.securityfocus.com/bid/20335
https://exchange.xforce.ibmcloud.com/vulnerabilities/28352