Lucene search

K
cveMitreCVE-2006-1889
HistoryApr 20, 2006 - 10:02 a.m.

CVE-2006-1889

2006-04-2010:02:00
mitre
web.nvd.nist.gov
25
cve-2006-1889
xss
web script injection
html injection
nils asmussen
boardsolution

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.006

Percentile

78.8%

Cross-site scripting (XSS) vulnerability in the search action handler in index.php in Nils Asmussen (aka SCRIPTSOLUTION) Boardsolution 1.12 and earlier allows remote attackers to inject arbitrary web script or HTML via the “Search for” item (keyword parameter).

Affected configurations

Nvd
Node
script-solution.deboardsolutionRange1.12
VendorProductVersionCPE
script-solution.deboardsolution*cpe:2.3:a:script-solution.de:boardsolution:*:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.006

Percentile

78.8%

Related for CVE-2006-1889