4.3

CVE-2006-5516

Exploit
Multiple cross-site scripting (XSS) vulnerabilities in actions/usersettings.php in WikiNi before 0.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) email parameters to wakka.php.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WikiniWikini Version0.4.2
WikiniWikini Version0.4.3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.53% 0.829
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:N/I:P/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://cvs.gna.org/cvsweb/wikini/actions/usersettings.php.diff?r1=1.14.2.1%3Br2=1.14.2.2%3Bcvsroot=wikini%3Bf=h
http://secunia.com/advisories/22558
Vendor Advisory
http://securityreason.com/securityalert/1776
http://securitytracker.com/id?1017116
http://www.securityfocus.com/archive/1/449518/100/0/threaded
http://www.securityfocus.com/bid/20688
Patch
Exploit
http://www.vupen.com/english/advisories/2006/4159
http://www.wikini.net/wakka.php?wiki=WikiNiChangeLog044
http://zone14.free.fr/advisories/6/
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/29761