Lucene search

K
cveMitreCVE-2006-2011
HistoryApr 25, 2006 - 12:50 p.m.

CVE-2006-2011

2006-04-2512:50:00
mitre
web.nvd.nist.gov
28
cve-2006-2011
cross-site scripting
xss vulnerability
4images 1.7
web security

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.009

Percentile

83.0%

Cross-site scripting (XSS) vulnerability in member.php in 4images 1.7 and earlier allows remote attackers to inject arbitrary web script or HTML via the nickname, probably involving the user_name parameter in register.php.

Affected configurations

Nvd
Node
4homepages4imagesMatch1.7
VendorProductVersionCPE
4homepages4images1.7cpe:2.3:a:4homepages:4images:1.7:*:*:*:*:*:*:*

CVSS2

2.6

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

AI Score

5.7

Confidence

High

EPSS

0.009

Percentile

83.0%

Related for CVE-2006-2011