4.3
CVE-2006-5294
- EPSS 2.42%
- Veröffentlicht 16.10.2006 18:07:00
- Zuletzt bearbeitet 16.06.2026 22:30:54
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitrary web script or HTML via the unsubscribeemail parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.42% | 0.82 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:N/I:P/A:N
|
http://mantis.phplist.com/changelog_page.php
http://secunia.com/advisories/22405
http://securityreason.com/securityalert/1728
http://tincan.co.uk/?lid=1821
http://websecurity.com.ua/267/
http://www.phplist.com/news
http://www.securityfocus.com/archive/1/448411/100/0/threaded
http://www.securityfocus.com/bid/20483
http://www.vupen.com/english/advisories/2006/4027