Lucene search

K
cveMitreCVE-2006-2969
HistoryJun 12, 2006 - 8:06 p.m.

CVE-2006-2969

2006-06-1220:06:00
mitre
web.nvd.nist.gov
29
cve-2006-2969
xss
remote attack
web script
html
img element
quickchat.php
security vulnerability

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.006

Percentile

78.3%

Cross-site scripting (XSS) vulnerability in L0j1k tinyMuw 0.1.0 allow remote attackers to inject arbitrary web script or HTML via a javascript URI in the SRC attribute of an IMG element in the input box in quickchat.php, and possibly other manipulations.

Affected configurations

Nvd
Node
l0j1ktinymuwMatch0.1.0
VendorProductVersionCPE
l0j1ktinymuw0.1.0cpe:2.3:a:l0j1k:tinymuw:0.1.0:*:*:*:*:*:*:*

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

AI Score

5.8

Confidence

High

EPSS

0.006

Percentile

78.3%

Related for CVE-2006-2969