4.3

CVE-2006-5071

Multiple cross-site scripting (XSS) vulnerabilities in eyeOS before 0.9.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving (1) eyeNav and (2) system/baixar.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Eyeos ProjectEyeos Version <= 0.9.0.6
Eyeos ProjectEyeos Version0.8.3
Eyeos ProjectEyeos Version0.8.3_r2
Eyeos ProjectEyeos Version0.8.4
Eyeos ProjectEyeos Version0.8.4_r1
Eyeos ProjectEyeos Version0.8.5
Eyeos ProjectEyeos Version0.8.9
Eyeos ProjectEyeos Version0.8.10
Eyeos ProjectEyeos Version0.9.0.1
Eyeos ProjectEyeos Version0.9.0.2
Eyeos ProjectEyeos Version0.9.0.3
Eyeos ProjectEyeos Version0.9.0.4
Eyeos ProjectEyeos Version0.9.0.5
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.26% 0.658
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://eyeos.blogspot.com/2006/09/eyeos-091-released.html
Patch
http://secunia.com/advisories/22117
Patch
Vendor Advisory
http://sourceforge.net/project/shownotes.php?group_id=145027&release_id=450490
Patch
http://www.securityfocus.com/bid/20213
Patch
http://www.vupen.com/english/advisories/2006/3780
https://exchange.xforce.ibmcloud.com/vulnerabilities/29190