6.8

CVE-2006-4577

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in The Address Book 1.04e allow remote attackers to inject arbitrary web script or HTML via Javascript events in the (1) email, (2) websites, and (3) groupAddName parameters in (a) save.php; the (4) errorMsg parameter in (b) index.php; and the (5) goTo and (6) search parameters in (c) search.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.58% 0.722
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/21694
Vendor Advisory
Exploit
http://secunia.com/secunia_research/2006-76/advisory/
Vendor Advisory
Exploit
http://www.securityfocus.com/bid/21870
http://osvdb.org/32564
http://osvdb.org/32565
http://osvdb.org/32566
https://exchange.xforce.ibmcloud.com/vulnerabilities/31240
https://exchange.xforce.ibmcloud.com/vulnerabilities/31247