6.8
CVE-2006-6375
- EPSS 1.57%
- Published 07.12.2006 17:28:00
- Last modified 09.04.2025 00:30:58
- Source cve@mitre.org
- Teams watchlist Login
- Open Login
Cross-site scripting (XSS) vulnerability in display.php in Simple Machines Forum (SMF) 1.1 Final and earlier allows remote attackers to inject arbitrary web script or HTML via the contents of a file that is uploaded with the image parameter set, which can be interpreted as script by Internet Explorer's automatic type detection.
Data is provided by the National Vulnerability Database (NVD)
Simple Machines ≫ Smf Version1.0.9
Simple Machines ≫ Smf Version1.0_beta5p
Simple Machines ≫ Smf Version1.1_final
Simple Machines ≫ Smf Version1.1_rc3
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 1.57% | 0.809 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|