Lucene search

K
cveMitreCVE-2006-2815
HistoryJun 05, 2006 - 5:02 p.m.

CVE-2006-2815

2006-06-0517:02:00
CWE-79
mitre
web.nvd.nist.gov
26
cve-2006-2815
xss
two shoes m-factory
simpleboard
mambo
joomla
remote attack
injection
web script
html
vulnerability

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.8

Confidence

High

EPSS

0.024

Percentile

90.0%

Multiple cross-site scripting (XSS) vulnerabilities in Two Shoes M-Factory (TSMF) SimpleBoard 1.1.0 Stable (aka com_simpleboard), as used in Mambo and Joomla!, allow remote attackers to inject arbitrary web script or HTML via (1) the Name field in “post ne topic” in the Frontend, (2) the Title (aka Community-Title) field in Simpleboard Configuration in the Backend Admin Panel, and the (3) Name (aka Forum-Title) and (4) Name (aka Category-Title) fields in Simpleboard Administration in the Backend Admin Panel. NOTE: some sources have stated that the sb_authorname parameter is affected, but it is unclear which field is related to it.

Affected configurations

Nvd
Node
two_shoes_mambo_factorysimpleboardMatch1.1.0_stable
VendorProductVersionCPE
two_shoes_mambo_factorysimpleboard1.1.0_stablecpe:2.3:a:two_shoes_mambo_factory:simpleboard:1.1.0_stable:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

AI Score

5.8

Confidence

High

EPSS

0.024

Percentile

90.0%

Related for CVE-2006-2815