6.8
CVE-2006-4964
- EPSS 1.41%
- Veröffentlicht 23.09.2006 10:07:00
- Zuletzt bearbeitet 16.06.2026 22:30:12
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in MAXdev MDPro 1.0.76 before 20060918 allows remote attackers to inject arbitrary web script or HTML via (1) vectors that bypass the XSS protection mechanisms of the pnVarCleanFromInput function, and (2) unspecified vectors related to the AntiCracker.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.41% | 0.691 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://jvn.jp/jp/JVN%2346630603/index.html
http://secunia.com/advisories/22050
http://www.maxdev.com/Article605.phtml
http://www.maxdev.com/Downloads-index-req-dldet-lid-497-ttitle-Security_fix_for_MDPro_1.076.phtml
http://www.securityfocus.com/bid/20133
http://www.vupen.com/english/advisories/2006/3732