Lucene search

K
cveMitreCVE-2006-0806
HistoryFeb 21, 2006 - 2:02 a.m.

CVE-2006-0806

2006-02-2102:02:00
CWE-79
mitre
web.nvd.nist.gov
48
xss
adodb
remote attack
web script
html
vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.253

Percentile

96.7%

Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow remote attackers to inject arbitrary web script or HTML via (1) the next_page parameter in adodb-pager.inc.php and (2) other unspecified vectors related to PHP_SELF.

Affected configurations

Nvd
Node
john_limadodbMatch4.66
OR
john_limadodbMatch4.68
OR
john_limadodbMatch4.70
OR
john_limadodbMatch4.71
VendorProductVersionCPE
john_limadodb4.66cpe:2.3:a:john_lim:adodb:4.66:*:*:*:*:*:*:*
john_limadodb4.68cpe:2.3:a:john_lim:adodb:4.68:*:*:*:*:*:*:*
john_limadodb4.70cpe:2.3:a:john_lim:adodb:4.70:*:*:*:*:*:*:*
john_limadodb4.71cpe:2.3:a:john_lim:adodb:4.71:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.5

Confidence

High

EPSS

0.253

Percentile

96.7%