6.8
CVE-2006-7050
- EPSS 1.4%
- Veröffentlicht 24.02.2007 00:28:00
- Zuletzt bearbeitet 16.06.2026 22:34:17
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Cross-site scripting (XSS) vulnerability in WikkaWiki (Wikka Wiki) before 1.1.6.2 allows remote attackers to inject arbitrary javascript via (1) events in forced links (url parameter) that are not properly handled in formatters/wakka.php, and possibly (2) other vectors in wikka.php.
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.4% | 0.69 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.8 | 8.6 | 6.4 |
AV:N/AC:M/Au:N/C:P/I:P/A:P
|
http://secunia.com/advisories/20628
http://wikkawiki.org/WikkaReleaseNotes
http://www.vupen.com/english/advisories/2006/2381
http://wush.net/trac/wikka/changeset/47
http://wush.net/trac/wikka/ticket/142
http://www.securityfocus.com/bid/18481
https://exchange.xforce.ibmcloud.com/vulnerabilities/27227