6.8
CVE-2006-6375
- EPSS 1.57%
- Veröffentlicht 07.12.2006 17:28:00
- Zuletzt bearbeitet 09.04.2025 00:30:58
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet Explorer's automatic type detection.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Simple Machines ≫ Smf Version1.0.9
Simple Machines ≫ Smf Version1.0_beta5p
Simple Machines ≫ Smf Version1.1_final
Simple Machines ≫ Smf Version1.1_rc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.57% | 0.809 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|