6.8

CVE-2006-5037

MySource Matrix after 3.8 allows remote attackers to use the application as an HTTP proxy server via a MIME encoded URL in the sq_content_src parameter to access arbitrary sites with the server's IP address and conduct cross-site scripting (XSS) attacks.  NOTE: the researcher reports that "The vendor does not consider this a vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SquizMysource Matrix Version3.8
SquizMysource Matrix Version3.8.2
SquizMysource Matrix Version3.8.3
SquizMysource Matrix Version3.8.4
SquizMysource Matrix Version3.8.5
SquizMysource Matrix Version3.8.6a
SquizMysource Matrix Version3.10
SquizMysource Matrix Version3.10.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.643
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/22060
http://securityreason.com/securityalert/1635
http://www.aushack.com/advisories/200607-mysourcematrix.txt
Vendor Advisory
http://www.securityfocus.com/archive/1/446722/100/0/threaded