6.8
CVE-2006-6649
- EPSS 1.5%
- Veröffentlicht 20.12.2006 02:28:00
- Zuletzt bearbeitet 16.06.2026 22:33:32
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in display.php in HyperVM 1.2 and earlier allows remote attackers to inject arbitrary web script or HTML via an encoded frm_action parameter. NOTE: the vendor disputes this issue, but it is not certain whether the dispute is about the severity of the issue, or its existence.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.5% | 0.709 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/23413
http://securityreason.com/securityalert/2051
http://www.aria-security.com/forum/showthread.php?p=89#post89
http://www.attrition.org/pipermail/vim/2006-December/001191.html
http://www.securityfocus.com/archive/1/454704/100/0/threaded
http://www.vupen.com/english/advisories/2006/5062