6.8
CVE-2006-5247
- EPSS 1.59%
- Veröffentlicht 12.10.2006 00:07:00
- Zuletzt bearbeitet 16.06.2026 22:30:49
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Multiple cross-site scripting (XSS) vulnerabilities in Eazy Cart allow remote attackers to inject arbitrary web script or HTML via easycart.php, possibly related to the (1) des and (2) qty parameters in an add action, and via other unspecified vectors. NOTE: some details are obtained from third party information.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.59% | 0.725 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/22286
http://securityreason.com/securityalert/1717
http://securitytracker.com/id?1017041
http://www.mayhemiclabs.com/advisories/MHL-2006-01.txt
http://www.mayhemiclabs.com/wiki/wikka.php?wakka=MHL2006001
http://www.securityfocus.com/archive/1/448094/100/0/threaded
https://exchange.xforce.ibmcloud.com/vulnerabilities/29421